Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cyberwarfare

France: Flame Malware Used in Attacks Against Government Officials, US Accused

State-sanctioned attackers broke into French government computers and illegally obtained top-secret information, according to an exclusive report in the French paper L’Express. The United States was behind the incident, the paper claimed.

State-sanctioned attackers broke into French government computers and illegally obtained top-secret information, according to an exclusive report in the French paper L’Express. The United States was behind the incident, the paper claimed.

Attackers used simple social engineering tactics to phish government officials working at the Élysée Palace for their login credentials, L’Express reported. The attackers used Facebook to identify people who worked at the presidential palace and connected with them on the social networking site. The victims considered the attackers as friends, making it even more likely that when the attackers sent an email invitation with a link to a Website, the victims would click on it. The fake site was a replica of the Élysée Palace site, and when prompted to enter the password, they did so, in “good faith,” according to L’Express.

Flame Malware in FranceWith login credentials in hand, the attackers were able to access the Élysée Palace network, and installed “spy software” which spread to other computers. The malware infected machines belonging to the “most influential advisers” in the French government, including Xavier Musca, the Secretary General, according to the report. The French president, Nicolas Sarkozy, was not infected because he didn’t have a networked Windows PC. The attackers then stole political and strategic data, L’Express said.

“We categorically refute allegations of unidentified sources,” Mitchell Moss, a spokesperson from the U.S. Embassy in Paris, told l’Express. “France is one of our best allies. Our cooperation is remarkable in the areas of intelligence, law enforcement and cyber defense. It has never been so good and remains essential to achieve our common fight against extremist threat.”

L’Express said the malware had the same features as Flame, the cyber-espionage tool discovered by Kaspersky Lab earlier this year.

The attack occurred in May, just before the second round of presidential elections in France. An unnamed official close to the investigation said the attack was likely related to France’s numerous political and economic agreements with foreign countries, including the Middle East. The attackers could have been trying to figure out how those agreements would be impacted if Sarkozy lost the election.

“You can be on good terms with a ‘friendly country’ and still wish to ensure its continued support, especially in a period of political transition,” an unnamed official told the magazine.

It took the French information security agency Anssi several days to clean and restore the network.

Department of Homeland Security secretary Janet Napolitano told L’Express in an interview that Flame and Stuxnet had “never been linked to the US government.”

Advertisement. Scroll to continue reading.

Stuxnet is widely believed to have been developed by the United States and Israel to damage, and halt Iran’s nuclear program. However, anonymous government officials reportedly confirmed to the New York Times this summer that Stuxnet was part of a joint US-operation codenamed Operation Olympic Games.

Kaspersky Lab believes Flame is related to Stuxnet because the two pieces of malware share a code module. Despite being discovered earlier, Kaspersky researchers believe Stuxnet was developed after Flame.

“We have no greater partner than France, we have no greater ally than France. We cooperate in many security-related areas. I am here to further reinforce those ties and create new ones,” Napolitano told L’Express.

Related: Connections Exist Between Cyber Weapons, But Secrets Remain

Related: Obama Ordered Use of Stuxnet Against Iran

Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Professional services company Slalom has appointed Christopher Burger as its first CISO.

Allied Universal announced that Deanna Steele has joined the company as CIO for North America.

Former DoD CISO Jack Wilmer has been named CEO of defensive and offensive cyber solutions provider SIXGEN.

More People On The Move

Expert Insights

Related Content

Cyberwarfare

WASHINGTON - Cyberattacks are the most serious threat facing the United States, even more so than terrorism, according to American defense experts. Almost half...

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Cyberwarfare

Russian espionage group Nomadic Octopus infiltrated a Tajikistani telecoms provider to spy on 18 entities, including government officials and public service infrastructures.

Cyberwarfare

Several hacker groups have joined in on the Israel-Hamas war that started over the weekend after the militant group launched a major attack.

Cyberwarfare

An engineer recruited by intelligence services reportedly used a water pump to deliver Stuxnet, which reportedly cost $1-2 billion to develop.

Application Security

Virtualization technology giant VMware on Tuesday shipped urgent updates to fix a trio of security problems in multiple software products, including a virtual machine...

Application Security

Fortinet on Monday issued an emergency patch to cover a severe vulnerability in its FortiOS SSL-VPN product, warning that hackers have already exploited the...

Cyberwarfare

The war in Ukraine is the first major conflagration between two technologically advanced powers in the age of cyber. It prompts us to question...