Flame, also known as Flamer and sKyWIper, is a highly sophisticated cyberespionage malware platform publicly exposed in 2012 and widely regarded as part of a broader state-linked espionage ecosystem associated with Stuxnet, Duqu, Gauss, and MiniFlame. It is notable for modular design, long-term intelligence collection, and advanced operational security. Flame has been linked through multiple technical and developmental relationships to other elite espionage operations, including evidence that an older Stuxnet variant incorporated a Flame component and reporting that Five Eyes counter-intrusion signatures explicitly tracked Flame and MiniFlame activity. Some later research has argued that Flame development continued after its 2012 exposure in a retooled form sometimes referred to as Flame 2.0, including 64-bit variants and stronger resource encryption, but those claims are less broadly established than the original platform’s existence and capabilities. Flame is associated with espionage-focused activity rather than financially motivated crime or ransomware. Its operators used it for covert collection from compromised systems and maintained a mature post-compromise capability set. Reported behaviors and relationships indicate extensive post-exploitation tradecraft, persistence, data theft, and defense evasion. Flame also became notable for using a cryptographic attack that allowed malware to impersonate a Windows Update server and spread as if legitimately signed by Microsoft, demonstrating unusually advanced initial-access and spoofing capability. Research comparing Flame with Agent.btz, Gauss, and MiniFlame also identified overlaps in USB-related data handling and naming conventions, suggesting awareness of or reuse of prior espionage tradecraft across multiple campaigns. Flame has been discussed in the context of a collaborative, multi-platform state cyber program rather than an isolated malware family. It is frequently analyzed alongside MiniFlame as a related sub-platform and alongside Stuxnet and Duqu as part of an interconnected development lineage. High-confidence public reporting supports Flame’s role as an advanced espionage framework used against targets in the Middle East and its significance as one of the most technically sophisticated malware platforms of its era.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Espionage malware referenced for similarities to Agent.BTZ, including XOR encryption and use of USB storage containers.
A modular cyberespionage platform tied into the broader GOSSIPGIRL cluster and Stuxnet development; later research in the article claims Flame survived via a retooled Flame 2.0.
A modular cyberespionage platform tied to the GOSSIPGIRL umbrella and Stuxnet collaboration; known for impersonating Windows Update via a cryptographic attack, deploying a SUICIDE cleanup module in 2012, and later resurfacing as Flame 2.0.
Referenced as a separate operator group/platform linked via shared exploit code/modules with Equation Group and Stuxnet (per Kaspersky’s linkage discussion).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.