Flame: Modern Warfare Matthew Stratton. What is Flame? How it was found What are its capabilities...

21
Flame: Modern Warfare Matthew Stratton

description

Flame’s Discovery This is not the malware you are looking for

Transcript of Flame: Modern Warfare Matthew Stratton. What is Flame? How it was found What are its capabilities...

Page 1: Flame: Modern Warfare Matthew Stratton. What is Flame? How it was found What are its capabilities How it is similar to Stuxnet and Duqu Implications.

Flame: Modern WarfareMatthew Stratton

Page 2: Flame: Modern Warfare Matthew Stratton. What is Flame? How it was found What are its capabilities How it is similar to Stuxnet and Duqu Implications.

What is Flame?

• How it was found

• What are its capabilities

• How it is similar to Stuxnet and Duqu

• Implications

Page 3: Flame: Modern Warfare Matthew Stratton. What is Flame? How it was found What are its capabilities How it is similar to Stuxnet and Duqu Implications.

Flame’s Discovery

This is not the malware you are looking for

Page 4: Flame: Modern Warfare Matthew Stratton. What is Flame? How it was found What are its capabilities How it is similar to Stuxnet and Duqu Implications.

Kaspersky Labs

• April, 2012• National Iranian Oil Company

infected by an unknown virus• International Telecommunication

Union asked Kaspersky to investigate

• Looked for a virus called “Wiper” but found something much worse

Page 5: Flame: Modern Warfare Matthew Stratton. What is Flame? How it was found What are its capabilities How it is similar to Stuxnet and Duqu Implications.

New Malware: Flame

• Kaspersky labs named the new virus “Flame” after the name of one of the prominent modules

Page 6: Flame: Modern Warfare Matthew Stratton. What is Flame? How it was found What are its capabilities How it is similar to Stuxnet and Duqu Implications.

Infected

• Most infected computers found in the Middle East

• A few infections found in Europe

Page 7: Flame: Modern Warfare Matthew Stratton. What is Flame? How it was found What are its capabilities How it is similar to Stuxnet and Duqu Implications.

Tried and True

• Flame has been in the wild a long time

• Evidence of Flame’s use as far back as August 2010– Avoided detection for 20+ months

• Likely much older, some evidence suggests earlier versions as early as 2007

Page 8: Flame: Modern Warfare Matthew Stratton. What is Flame? How it was found What are its capabilities How it is similar to Stuxnet and Duqu Implications.

Flame’s Capabilities

Spy in a Box

Page 9: Flame: Modern Warfare Matthew Stratton. What is Flame? How it was found What are its capabilities How it is similar to Stuxnet and Duqu Implications.

What is Flame

• Sophisticated attack toolkit: backdoor, trojan, worm

• Avoids detection• Modular:

– Small infection module downloads extra modules once it compromises a system

– With all known modules: ~20 MB in size– Wiper may be a Flame module

Page 10: Flame: Modern Warfare Matthew Stratton. What is Flame? How it was found What are its capabilities How it is similar to Stuxnet and Duqu Implications.

Infect

• Signed by fraudulent certificate supposedly from Microsoft Enforced Licensing Intermediate PCA certificate authority

• Infection module will modify itself to avoid antivirus detection

• Large size makes it hard to determine that Flame is doing anything malicious

Page 11: Flame: Modern Warfare Matthew Stratton. What is Flame? How it was found What are its capabilities How it is similar to Stuxnet and Duqu Implications.

Gather

• Once a machine is infected, attack modules downloaded from C&C server depending on the target system

• Sniff network traffic and gather information on Bluetooth devices in range– Could lead to customized attacks in the

future

Page 12: Flame: Modern Warfare Matthew Stratton. What is Flame? How it was found What are its capabilities How it is similar to Stuxnet and Duqu Implications.

Gather

• Take screenshots when “interesting” applications are running

• Turn on built in mic and record audio conversations

• Key logger• Record Skype conversations• Gather local files stored on computer,

including info from databases

Page 13: Flame: Modern Warfare Matthew Stratton. What is Flame? How it was found What are its capabilities How it is similar to Stuxnet and Duqu Implications.

Spread

• On command of the operator (C&C server)

Page 14: Flame: Modern Warfare Matthew Stratton. What is Flame? How it was found What are its capabilities How it is similar to Stuxnet and Duqu Implications.

Notorious Similarities

Stuxnet and Duqu

Page 15: Flame: Modern Warfare Matthew Stratton. What is Flame? How it was found What are its capabilities How it is similar to Stuxnet and Duqu Implications.

Stuxnet and Duqu

• Sophistication• Exploit same vulnerabilities

– Print spooler– USB infection methods– Not seen anywhere else

Page 16: Flame: Modern Warfare Matthew Stratton. What is Flame? How it was found What are its capabilities How it is similar to Stuxnet and Duqu Implications.

Different Developers

• Different programming language• Different software architecture• Hypothesis:

– Developed in parallel with Stuxnet and Duqu by different teams

– Access to same database of vulnerabilities

– Both commisioned by same group

Page 17: Flame: Modern Warfare Matthew Stratton. What is Flame? How it was found What are its capabilities How it is similar to Stuxnet and Duqu Implications.

Implications

The Dawn of Cyber Warfare

Page 18: Flame: Modern Warfare Matthew Stratton. What is Flame? How it was found What are its capabilities How it is similar to Stuxnet and Duqu Implications.

Cyber Warfare

• "actions by a nation-state to penetrate another nation's computers or networks for the purposes of causing damage or disruption."

• Developed by a nation state– Complexity– Goals– Targets

Page 19: Flame: Modern Warfare Matthew Stratton. What is Flame? How it was found What are its capabilities How it is similar to Stuxnet and Duqu Implications.

Creators

• Leaked documents and inside sources claim it was a project started by George W. Bush and continued by President Obama– Olympic Games– Developed with Israel

• No one has openly claimed responsibility

Page 20: Flame: Modern Warfare Matthew Stratton. What is Flame? How it was found What are its capabilities How it is similar to Stuxnet and Duqu Implications.

Fin

• Finding Flame

• Flame’s functionality

• Connections to Stuxnet and Duqu

• Implications: Cyber Warfare

Page 21: Flame: Modern Warfare Matthew Stratton. What is Flame? How it was found What are its capabilities How it is similar to Stuxnet and Duqu Implications.

Questions?