Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

dipsydoodle

(42,239 posts)
Fri Jun 8, 2012, 12:19 PM Jun 2012

Flame malware makers send 'suicide' code

Source: BBC News

The creators of the Flame malware have sent a "suicide" command that removes it from some infected computers.

Security firm Symantec caught the command using booby-trapped computers set up to watch Flame's actions.

Flame came to light after the UN's telecoms body asked for help with identifying a virus found stealing data from many PCs in the Middle East.

New analysis of Flame reveals how sophisticated the program is and gives hints about who created it.

Read more: http://www.bbc.co.uk/news/technology-18365844

14 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies

Response to HopeHoops (Reply #1)

 

Purveyor

(29,876 posts)
3. And if linked to a nation state, we would consider it an 'act of war' and naval fleets would be
Fri Jun 8, 2012, 12:41 PM
Jun 2012

repositioned.

dixiegrrrrl

(60,010 posts)
12. BBC sure is covering for USA and Israel on this one
Fri Jun 8, 2012, 03:11 PM
Jun 2012

or else is totally ignorant.
The BBC article claims the Flame creators are unknown AND claims Israel was a victim of Flame,
while the nytimes ( the link about by neohippie) has quite a few fascinating articles on why the USA and Israel created the virus.

 

HopeHoops

(47,675 posts)
4. Not exactly what I mean. If it can send out a suicide code it can interrupt efforts to combat it.
Fri Jun 8, 2012, 12:43 PM
Jun 2012

I haven't heard of malware doing that before. It's clever, but insidious.

dipsydoodle

(42,239 posts)
8. Not so much to combat it.
Fri Jun 8, 2012, 01:01 PM
Jun 2012

A failed attempt to prevent it from being re-used. Failed because they failed to acknowledge the speed at which it had already been broken down and analysed - it may well be at least be partly ready for re-use anyway.

As one of life's great believers in retribution hopefully whoever put it together in the first place gets their just blow back and in future takes care of what they wish.

 

HopeHoops

(47,675 posts)
9. Well, to be fair, M$ has had plenty of infections in their headquarters - on their own OSs.
Fri Jun 8, 2012, 01:08 PM
Jun 2012

Paybacks are hell when they happen.

dipsydoodle

(42,239 posts)
14. Here's how it was done - fake digital certificate
Fri Jun 8, 2012, 06:33 PM
Jun 2012

World’s best cryptography brains behind Flame spy virus.

The spy malware Flame used bogus Microsoft certificates to infect new computers, a prominent cybersecurity expert says. The science needed to pull the trick probably required some of the world’s best knowledge of cryptography.

The virus, which spread across the Middle East and particularly Iran, can mask itself as legitimate patches distributed through a Windows Update, reports Marc Stevens from the Centrum Wiskunde & Informatica (CWI) in Amsterdam.

It does so by providing a fake digital certificate, stating that the malware is a code originating from a trusted producer, which appears to have been issued by Microsoft itself.

Obtaining such a fraudulent certificate required a so-called chosen-prefix collision attack. It’s an attack targeting a specific cybersecurity algorithm called Message-Digest algorithm 5, or MD5. MD5 basically takes a piece of data and turns it into a unique digital fingerprint called a hash.

http://www.rt.com/news/flame-virus-windows-updates-346/

Latest Discussions»Latest Breaking News»Flame malware makers send...