Lilith Lela on Tumblr

  • Disclaimer
  • Links
  • Random
  • Archive
  • RSS
  • Ask
  • Post

‘Gadget’ in the middle: Flame malware spreading vector identified

Aleks, June 04

In our FAQ on Flame posted on May 28, 2012, we postulated there might be a still undiscovered zero-day vulnerability in Flame:

“At the moment, we haven’t seen use of any 0-days; however, the worm is known to have infected fully-patched Windows 7 systems through the network, which might indicate the presence of a high risk 0-day.”

Our suspicion was heightened because fully patched Windows 7 machines were being infected over the network in a very suspicious manner.

We can now confirm this is the main purpose of a special module of Flame called “Gadget” together with another module called “Munch”.

(NOTE: It’s important to understand that the initial Flame infection could still be happening through zero-day vulnerabilities. The “Gadget” module is simply used to spread within a network from a machine that is already infected with the malware).

The “Gadget” and “Munch” modules implement an interesting man-in-the-middle attack against other computers in a network.

When a machine tries to connect to Microsoft’s Windows Update, it redirects the connection through an infected machine and it sends a fake, malicious Windows Update to the client.

The fake update claims to be the following:

“update description=”Allows you to display gadgets on your desktop.” 
displayName=”Desktop Gadget Platform” name=”WindowsGadgetPlatform”

[…]

Important information: One June 4th, 2012, Microsoft released a number of blog posts and an Update for Windows which is blocking three fraudulent certificates used by Flame. We recommend that Windows users apply this update immediately.

Microsoft SRD blog:http://blogs.technet.com/b/srd/archive/2012/06/03/microsoft-certification-authority-signing-certificates-added-to-the-untrusted-certificate-store.aspx

Microsoft security advisory 2718704:http://technet.microsoft.com/en-us/security/advisory/2718704

MSRC blog:http://blogs.technet.com/b/msrc/archive/2012/06/03/microsoft-releases-security-advisory-2718704.aspx

SecureList: ‘Gadget’ in the middle: Flame malware spreading vector identified

    • #flame
    • #certificate
  • 11 months ago
  • 9
  • Permalink
  • Share
    Tweet

9 Notes/ Hide

  1. netzblockierer reblogged this from lilithlela
  2. netzblockierer likes this
  3. fivedee reblogged this from anonymissexpress
  4. fivedee likes this
  5. dom72 reblogged this from anonymissexpress
  6. dom72 likes this
  7. fromstarstostarfish likes this
  8. theamericanbear likes this
  9. anonymissexpress reblogged this from lilithlela and added:
    Aleks, June 04 SecureList: ‘Gadget’ in the middle: Flame malware spreading vector identified
  10. lilithlela posted this
← Previous • Next →

If complete and utter chaos was lightning, I'd be the one standing barefeet on a hilltop in a thunderstorm wearing wet copper armour, holding a lightning rod and shouting "Whatever! Bring it on, ye gods and goddesses!"

The wind howled. Lightning stabbed at the earth erratically, like an inefficient assassin. Thunder rolled back and forth across the dark, rain-lashed sky …

Elsewhere

  • @lilithlela on Twitter
  • lilithlela on Youtube
  • Google

Twitter

loading tweets…

Following

I Dig These Posts

See more →
  • Photo via waterman12053

    10knotes:

    This is why you marry your best friend.

    I have to reblog this. I am bound by a code.

    This post has been featured on a ...

    Photo via waterman12053
  • Photo via girtabaix

    mon coup de coeur du soir ! Bonsoir !

    Photo via girtabaix
  • Photo via ladylilith333

    funnywildlife:

    Hummingbird Feeding on Salvia_RGB4986 by DansPhotoArt on Flickr.

    Photo via ladylilith333
  • Photo via operationfahrenheit

    there is no business to be done on a dead planet

    Photo via operationfahrenheit
  • Photo via operationfahrenheit
    Photo via operationfahrenheit
  • RSS
  • Random
  • Archive
  • Ask
  • Post
  • Mobile

http://creativecommons.org/publicdomain/zero/1.0/ CC0 1.0 Universal Public Domain Dedication. Effector Theme by Carlo Franco.

Powered by Tumblr