Infection Channel: Propagates via removable drives
This info-stealing malware is dubbed as Flame malware and has been spotted in Iran and other countries since 2010. It is a multi-component threat which makes it hard to analyze.
To get a one-glance comprehensive view of the behavior of this Worm, refer to the Threat Diagram shown below.

This worm is capable of propagating in a local network when an infected machine is found in the said network. It also spreads through removable drives.
It may disable antivirus software by uninstalling registry keys. It is also capable of capturing screenshots, recording audio via the system's microphone, and manipulating a database that may contain records related to the malware’s malicious routines.
This worm arrives by connecting affected removable drives to a system or through an infected machine in the network.
This worm arrives by connecting affected removable drives to a system.
Connect with us on
| | | |