Audio By Carbonatix
The creators of the Flame malware have sent a "suicide" command that removes it from some infected computers.
Security firm Symantec caught the command using booby-trapped computers set up to watch Flame's actions.
Flame came to light after the UN's telecoms body asked for help with identifying a virus found stealing data from many PCs in the Middle East.
New analysis of Flame reveals how sophisticated the program is and gives hints about who created it.
Clean machine
Like many other security firms Symantec has kept an eye on Flame using so-called "honeypot" computers that report what happens when they are infected with a malicious program.
Described as a very sophisticated cyber-attack, Flame targeted countries such as Iran and Israel and sought to steal large amounts of sensitive data.
Earlier this week Symantec noticed that some Flame command and control (C&C) computers sent an urgent command to the infected PCs they were overseeing.
Flame's creators do not have access to all their C&C computers as security firms have won control of some of them.
The "suicide" command was "designed to completely remove Flame from the compromised computer", said Symantec.
The command located every Flame file sitting on a PC, removed it and then overwrote memory locations with gibberish to thwart forensic examination.
"It tries to leave no traces of the infection behind," wrote the firm on its blog.
Analysis of the clean-up routine suggested it was written in early May, said Symantec.
Crypto crash
At the same time, analysis of the inner workings of Flame reveal just how sophisticated it is.
According to cryptographic experts, Flame is the first malicious program to use an obscure cryptographic technique known as "prefix collision attack". This allowed the virus to fake digital credentials that had helped it to spread.
The exact method of carrying out such an attack was only demonstrated in 2008 and the creators of Flame came up with their own variant.
"The design of this new variant required world-class cryptanalysis," said cryptoexpert Marc Stevens from the Centrum Wiskunde & Informatica (CWI) in Amsterdam in a statement.
The finding gives support to claims that Flame must have been built by a nation state rather than cybercriminals because of the amount of time, effort and resources that must have been put into its creation. It is not yet clear which nation created the program.
DISCLAIMER: The Views, Comments, Opinions, Contributions and Statements made by Readers and Contributors on this platform do not necessarily represent the views or policy of Multimedia Group Limited.
Tags:
DISCLAIMER: The Views, Comments, Opinions, Contributions and Statements made by Readers and Contributors on this platform do not necessarily represent the views or policy of Multimedia Group Limited.
Latest Stories
-
NADMO dismisses claims residents were not warned before Weija Dam spillage
58 minutes -
Government begins payment of 2020 batch of nurses and midwives arrears
1 hour -
Controversial anti-LGBTQ bill presented to Parliament for second reading
1 hour -
Deloitte Partner urges clear, consistent policies to govern mining license renewals, local content
1 hour -
Xenophobic attacks: Ghana must pursue justice for victims beyond evacuation – Bosome Freho MP
2 hours -
BOPP positions sustainable agribusiness as investment frontier
2 hours -
Ga Mantse demands action against chiefs selling lands on waterways
2 hours -
South African Tourism condemns anti-immigrant attacks, reassures African travellers
2 hours -
APSU 2002 Year Group announces key leadership appointments for 97th anniversary hosting & BOLT Steering Committee
2 hours -
Government backs hybrid model for Ghana’s extractive sector, rejects move to shut out foreign investors
2 hours -
LMWG commends Heath Goldfields on 5-year community development plan for Prestea
2 hours -
Eswatini champions SiSwati stories in digital age at World Book Day 2026
2 hours -
Only weak men forgive cheating partner – Yul Edochie
2 hours -
Meta repeatedly snubs EU body over Facebook and Instagram user bans
2 hours -
Family wealth should be viewed as asset class for building transgenerational enterprises – Alex Dadey
3 hours