Flame creators make virus commit ‘suicide'

But, there is no trace on infected computers

June 11, 2012 12:35 am | Updated 12:39 am IST - LONDON:

The creators of the world's most complicated espionage virus, Flame, have sent a ‘suicide' command that removes it from some infected computers.

Security firm Symantec caught the command using booby-trapped computers set up to watch Flame's actions.

Like other security firms, Symantec has kept an eye on Flame using so-called ‘honeypot' computers that report what happens when they are infected with a malicious program.

According to Symantec, the ‘suicide' command was “designed to completely remove Flame from the compromised computer,” the BBC reports.

The command located every Flame file sitting on a PC, removed it and then overwrote memory locations with gibberish to thwart forensic examination. “It tries to leave no traces of the infection behind,” Symantec wrote on its blog.

Flame came to light last week after the U.N.'s telecom body asked for help in spotting a virus found stealing data from many PCs in the Middle East. Analysts who have investigated the virus said Flame, also called Skywiper, was one of the most complex computer espionage threats ever seen.

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.