Flame malware is the latest weapon of apparent state-sponsored cyber war.
In Ian Fleming’s universe of James Bond, the character Q – standing for “Quartermaster” and for so many years played in the film adaptations by Desmond Llewellyn – provides Agent 007 with all of the gadgets and just-out-of-reach-from-the-real-world technological tools he needs to achieve the goals of Her Majesty’s Secret Service. One of the most amazing things about Q’s technological wizardry was how it would always bend – but never break – our sense of believability. We always got the sense that, although a laser-watch or invisible car were not yet feasible, they were on the cusp of being everyday technologies.
MORE: Heavy Lies the Crown: Apple’s Mobile Success Puts it on Thin Security Ice
Moving to the world of information security, we’re beginning to see a blurring of the line that exists between amazing Q-like offensive security weapons, and the actual tools that are available to attackers. While Stuxnet and its cousin DuQu were considered the first major salvo fired in what could be described as state-sponsored cyber offense (I hesitate to use the term “cyber war”), the recently-discovered Flame malware represents a whole new level of seemingly out-of-reach offensive security weapons.
MORE: Decrypting the 2012 Verizon Data Breach Investigative Report
First, the basic details: as reported by Kaspersky Labs, Flame is malware that has been deployed primarily to systems in the Middle East and Africa. The malware itself is fairly large (over 20MB with all modules installed … more on that later), and contains code in a variety of programming languages including Lua (yes, the same Lua that is used to script in World of Warcraft) as well as libraries for features such as compression and SQL database manipulation.
What makes Flame really different is its payload. Flame is a modular, highly complex (estimated at 20 times more complex than Stuxnet, according to Kaspersky) system that provides over 20 plug-ins for various capabilities, most of them related to information theft. Unlike a traditional rootkit that limits itself to privilege escalation and establishing remote connectivity (leaving the details of data egress to the owner of the command-and-control network), Flame includes out-of-box capabilities for unique methods of actually collecting and recording data. This includes enabling and recording audio, Bluetooth management (including the ability to enable the infected host’s Bluetooth beacon), screenshot capture and more. And of course, it contains propagation code designed to spread itself to other local systems. In short, this is the cyber equivalent of the type of James Bond-like surveillance that our man Q would always deliver.
But there’s one more aspect of Flame that makes it even more like one of Q’s advanced technological tools: it is likely the product of a nation-state. When you think about it, there are basically four categories of attackers in the information security world: the casual tinkerers interested in simply seeing what they can find, hacktivists who are bent on bringing down a specific institution or business sector, organized criminals who want to monetize offensive security, and nation-states. The sheer size and complexity of Flame virtually eliminates the first two groups. The fact that none of the known modules within the toolkit are focused on monetization eliminates the third. That leaves one or more countries with a lot of money, who can spend a lot of time developing a complex, framework-based system. So, while I and others may hesitate to use such a loaded term as “cyber war,” perhaps it’s time to re-evaluate that stance.
As Q will tell you, in the world of cyber security, it’s not the field agents you necessarily need to worry about – it’s the people developing the tools they use.




