Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

Renew Deal

(81,870 posts)
Wed Jun 13, 2012, 03:16 PM Jun 2012

Flame stashes secrets in USB drives

<snip>
The Flame attack, however, takes the infection of removable media to another level.

In an ongoing analysis of the attack, security firm BitDefender has pinpointed a component of Flame that uses removable media as a carrier to sneak data out of secure installations. On computers not connected to the Internet -- a potential sign that the system is part of a sensitive, "airgapped" network -- Flame waits until a USB drive is inserted. Then it copies not only itself, but a prioritized list of stolen data as well.
<snip>

If a Flame-infected computer cannot connect to the Internet, it will infect any USB drive mounted by the system. Once infected, the attack will then copy files from the system to the drive, giving Word, Excel, and PowerPoint documents highest priority. If the drive still has space, it will copy CAD files and, last, JPEG files.

When the infected drive is inserted into another computer, it could spread the Flame virus -- although that functionality seems to be inactive. Instead, the program will attempt to connect to the Internet only on systems already infected. If Flame cannot communicate to the command-and-control servers, it will again copy files, clearing lower-priority documents to make space for additional data.

If the new system can connect to the command-and-control server, then Flame will copy the USB drive's contents to the computer. Its task is complete.
<snip>

http://www.infoworld.com/t/malware/flame-stashes-secrets-in-usb-drives-195455

2 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Flame stashes secrets in USB drives (Original Post) Renew Deal Jun 2012 OP
What is the easiest way to determine if a machine is infected? shcrane71 Jun 2012 #1
Which is why I take every USB drive I have and put it in my Linux machine and format it hobbit709 Jun 2012 #2

shcrane71

(1,721 posts)
1. What is the easiest way to determine if a machine is infected?
Thu Jun 14, 2012, 11:01 AM
Jun 2012

How can one determine if a USB drive is infected?

hobbit709

(41,694 posts)
2. Which is why I take every USB drive I have and put it in my Linux machine and format it
Fri Jun 15, 2012, 07:37 AM
Jun 2012

before I use it to copy data from a Windows PC. That eliminates the possibility of some kind of buried virus even on a new flash drive. My main Windows machine I know is clean. I also keep copies of all my data files on a computer that is NOT connected to the outside world.

I also have autorun turned off.

Latest Discussions»Help & Search»Computer Help and Support»Flame stashes secrets in ...