Report: CIA, NSA and Israeli Military Responsible for ‘Flame’ Malware Found in Iran
- Posted on June 20, 2012 at 11:57am by
Liz Klimas
- Print »
- Email »
When news of the Flame malware began making headlines at the end of May, it was suspected the U.S. and/or Israeli governments were involved in the virus that attacked systems, most of which were identified in Iran. Now, sources are formally accusing the U.S. Central Intelligence Agency, the National Security Agency and the Israeli military for their involvement in creating the cyber threat, also saying it is merely laying the groundwork for something bigger.
(Related: ‘One of the most complex threats ever discovered’: New cyber weapon found in Iran)
The Washington Post reports a former intelligence official, who spoke on the condition of anonymity, saying Flame “is about preparing the battlefield for another type of covert action.”

Distribution of systems infected with Flame malware. (Image: Kaspersky Labs)
When Flame was first being discovered, it was found to pre-date even the infamous Stuxnet worm, which was built to attack Iran’s nuclear program in 2010. Now, Kaspersky Labs, which has been leading the charge in researching Flame, has said it is absolutely sure the two viruses were created by those who also made Stuxnet. According to a report released by the security researchers last week, they were able to find some of the same code present in both Flame and Stuxnet. The Post has more from Kaspersky on the relation of the two bits of malware:
“We are now 100 percent sure that the Stuxnet and Flame groups worked together,” said Roel Schouwenberg, a Boston-based senior researcher with Kaspersky Lab.
The firm also determined that the Flame malware predates Stuxnet. “It looks like the Flame platform was used as a kickstarter of sorts to get the Stuxnet project going,” Schouwenberg said.
Here’s what Kaspersky said in its report:
The discovery of the Flame malware in May 2012 revealed the most complex cyber-weapon to date. At the time of its discovery, there was no strong evidence of Flame being developed by the same team that delivered Stuxnet and Duqu. The approach to the development of Flame and Duqu/Stuxnet was different as well, which lead to the conclusion that these projects were created by separate teams. However, the following in-depth research, conducted by Kaspersky Lab’s experts, reveals that these teams in fact cooperated at least once during the early stages of development.

How Flame infects systems. (Image: Kaspersky Labs)
The presence of Flame quickly became apparent after an oil refinery in Tehran was taken offline completely for a time after suffering a cyber attack. Although both the U.S. and Israel allegedly created the virus — none of the agencies contacted by the Post provided a statement — it is reported that Israel was= working alone to cause this minor disruption at the oil refinery in April. The Post reports U.S. officials saying they were “dismayed” by this one-sided decision that ultimately lead to the discovery of Flame.
According to the Post, this incident “shows the importance of mapping networks and collecting intelligence on targets as the prelude to an attack, especially in closed computer networks.”
Read more details in the Washington Post report here.
(H/T: SlashGear)



















Submitting your tip... please wait!
Tree_Butcher
Posted on June 20, 2012 at 9:51pmBusinesses have been under cyber attacks and cyber espionage for years and that this was the third front on the war on terror. It only follows that nation states would be doing the same. I do not condemn the action of Israel or the US on dangerous regimes such as these that have been targeted, but I do condemn the leaks.
The disturbing thought is if the governments that developed and launched this malware turned it against their own people and their accounts for their money and property, and against their phones and systems for their info.
I trust my government as far as I can throw it, and these rogue nations less.
Report Post »As the minutemen owned rifles over 200 years ago, so must we arm ourselves with knowing how these attacks can hit our own systems at home, and how to defend ourselves.
slr4528
Posted on June 20, 2012 at 8:58pmWhy aren’t people going to jail for disclosing US secrets???????
Report Post »TACHYON
Posted on June 21, 2012 at 12:05amIt’s part of the game to make U.S. citizens hate their government.
Report Post »AUsername
Posted on June 20, 2012 at 2:37pmits better than all out war but criminal actions to an innocent country should still not happen. its not cyber terrorism when the goverment does it.
Report Post »DrFrost
Posted on June 20, 2012 at 3:04pmIran has been openly threatening Israel. Furthermore, they’ve specifically stated an intent to use nuclear weapons against Israel. I think this response, if anything, was restrained.
Report Post »TACHYON
Posted on June 21, 2012 at 12:08amIt’s not criminal when a government does it to protect you from countries that secretly and publicly proclaim to want to kill you.
http://www.homelandsecurityus.com/PDF/GovtExM.pdf
Read part 4 of page 7 of 18 or 21 / 32
Report Post »SageInWaiting
Posted on June 20, 2012 at 1:12pmIf I had a clearance and talked about information like this, even if it were 30 years ago, I‘d end up in jail so fast that I wouldn’t know what happened. This is TREASON, folks… our methods have been compromised; what took YEARS to established has been lost…. and we have @SSHOLES WHO ARE DESCRIBING EXACTLY HOW IT WAS DONE!!!
People in this government war ACTIVELY working for the downfall of this country. HOW ELSE can THIS be explained. Not by incompetence. Not by an accident. This is blatant, willful TREASON!
(I better be careful or I’ll tell you what I REALLY feel and think.)
Report Post »