Kaspersky Lab disclosed Flame (also tracked as Flamer and Skywiper), a large modular espionage platform that infected Windows systems across the Middle East, with the highest known concentration in Iran and additional victims in Israel/Palestine, Sudan, Syria, Lebanon, Saudi Arabia, and Egypt. Researchers and Iranian officials said the malware was built for covert intelligence collection rather than direct disruption, with capabilities including keystroke logging, screenshots, password theft, network sniffing, Skype and instant-message monitoring, audio recording through infected microphones, Bluetooth data collection, and theft of documents and system architecture data. The campaign was described as exceptionally sophisticated, using multiple encryption schemes, forged Microsoft certificates, abuse of Windows Update, USB-based movement, and a modular design that allowed operators to expand surveillance while remaining hidden for years.
Reporting by The Washington Post said U.S. and Israeli officials developed Flame as part of a broader cyber campaign tied to efforts to slow Iran’s nuclear program, alongside operations associated with Stuxnet. Officials and researchers said Flame mapped Iranian networks and exfiltrated intelligence to support sabotage planning, while technical analysis found overlaps with Stuxnet-era tooling even as some experts assessed the malware was built by a parallel team. After public exposure, operators reportedly pushed a kill module to infected systems to remove the malware and overwrite artifacts, complicating forensic investigation and underscoring the operation’s state-grade tradecraft.

TTPs, infrastructure, and targeting history in one profile.
9 events from the most recent confirmed update back to the earliest known activity.
The Washington Post reported, citing Western officials, that the United States and Israel jointly developed Flame as part of a broader cyber campaign against Iran. According to the report, Flame gathered intelligence to support efforts to slow Iran's nuclear program.
By June 2012, researchers had identified code overlap and related technologies connecting Flame with Stuxnet-era malware, though some analysts still believed separate teams may have developed them in parallel. The findings strengthened suspicions of a shared state-sponsored ecosystem behind the campaigns.
In June 2012, Flame's operators instructed infected systems to install a removal component that deleted the malware and overwrote related file locations with random data. The action appeared intended to hinder forensic analysis after public exposure.
Subsequent technical analysis showed Flame abused Microsoft trust mechanisms by using a forged MD5-based certificate to sign malicious code and a module that intercepted Windows Update requests. The finding demonstrated that the campaign could undermine trusted software update channels as part of its espionage operations.
Iranian officials and CERT personnel said Flame had penetrated computers used by high-ranking Iranian officials and called it one of the country's most serious cyber incidents since Stuxnet. They said the malware was built for covert intelligence gathering rather than direct sabotage and that the campaign was still active.
On 2012-05-28, Iran's CERT/MAHER announced it had identified the previously undisclosed Flame malware during investigations tied to Stuxnet and Duqu. MAHER said tested antivirus products were not detecting the malware, so it developed and distributed its own detection tool and prepared a removal utility while assessing Flame as closely related to Stuxnet and Duqu.
Kaspersky Lab publicly revealed Flame in late May 2012 after investigating data-wiping malware in the Middle East at the request of the UN's International Telecommunication Union. Researchers described it as a massive, highly sophisticated cyber-espionage toolkit affecting multiple countries, especially Iran.
Before Flame was publicly identified, Iran detected cyberattacks on its oil industry, an episode later described as part of the context in which the malware surfaced. U.S. and Western officials cited by later reporting said the disruption was directed by Israel in a unilateral operation.
Security researchers later assessed that Flame had been active since at least August 2010, operating as a modular espionage platform across Middle Eastern targets. It was designed for covert intelligence collection, including surveillance, credential theft, and data exfiltration.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
10 references tracked. Mallory keeps watching after this page renders.
radware.com
Open sourcepcmag.com
Open sourcesecurelist.com
Open sourcewashingtonpost.com
Open sourceweb.archive.org
Open sourceweb.archive.org
Open sourceweb.archive.org
Open sourceweb.archive.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.