Kaspersky blog has more info: http://www.securelist.com/en/blog/208193522/The_Flame_Questi...
Flame: Massive cyber-attack discovered, researchers say
21–30 of 84 posts
Re: Flame: Massive cyber-attack discovered, researchers say
#22More technical details (pdf) on: http://www.crysys.hu/skywiper/skywiper.pdf Although the naming differs it has been noted on several blogs that it is the same malware.
I always hesitate a little bit when I open a pdf, specially when it is one on malware
Re: Flame: Massive cyber-attack discovered, researchers say
#23Re: Flame: Massive cyber-attack discovered, researchers say
#24We should just convert the comments to a poll. Who is behind this?
Re: Flame: Massive cyber-attack discovered, researchers say
#25We should just convert the comments to a poll. Who is behind this?
Re: Flame: Massive cyber-attack discovered, researchers say
#26We should just convert the comments to a poll. Who is behind this?
Re: Flame: Massive cyber-attack discovered, researchers say
#27We should just convert the comments to a poll. Who is behind this?
Re: Flame: Massive cyber-attack discovered, researchers say
#28They should do project estimation instead of Security Analysis.
Re: Flame: Massive cyber-attack discovered, researchers say
#29Earlier quoted context omitted.
I always hesitate a little bit when I open a pdf, specially when it is one on malware
Would opening a pdf via Chrome for example provide any extra protection? From what I understand most of the exploits are because of embedded media, no?
Re: Flame: Massive cyber-attack discovered, researchers say
#30Earlier quoted context omitted.
The LUA makes me wonder if the creator could be identified by their coding style.
From the Kaspersky article, Flame ships with a Lua VM, sqlite3, zlib, libbz2, and an SSL library (probably OpenSSL?), and these and more apparently result in its unusually large size (almost 20 MB). Sounds almost like "lean malware" written by a relatively small team using easily available tools and libraries.
Even better if the scripts can then be updated remotely as well.
All things considered, this is the kind of thing you'd do if you were going to do this long term.