New virus found spying on Middle East financial transactions

0
6060
Spread the love
gauss virus stuxnet flame duqu
The great complexity of the worm has caused much speculation over the possible perpetrators: very probably the virus has been conceived with the support of a nation state. Image – Socks-studio.com

A leading computer security firm has found a new cyber surveillance virus in the Middle East that spies on financial transactions, email and social networking activity, reports said on Thursday.

The Kaspersky Lab said the virus named “Gauss” may also be capable of attacking critical infrastructure and was built in the same laboratories as Stuxnet, the computer worm widely believed to have been used by the United States and Israel to attack Iran’s nuclear programme.

The Moscow-based firm said it found Gauss had infected personal computers in Lebanon, Israel and the Occupied Palestinian Territories. It declined to speculate on who was behind the virus but said it was related to Stuxnet and two other cyber espionage tools, Flame and Duqu.

“After looking at Stuxnet, Duqu and Flame, we can say with a high degree of certainty that Gauss comes from the same ‘factory’ or ‘factories,'” Kaspersky Lab said in a posting on its website. “All these attack toolkits represent the high end of nation-state-sponsored cyber-espionage and cyber war operations.”

Kaspersky Lab’s findings are likely to fuel a growing international debate over the development and use of cyber weapons. Those discussions were stirred up by the discovery of Flame in May by Kaspersky and others. Washington has declined comment on whether it was behind Stuxnet.

“Gauss can steal Internet browser passwords and other data, send information about system configurations, steal credentials for accessing banking systems in the Middle East, and hijack login information for social networking sites, email and instant messaging accounts,” Kaspersky Lab said in its report.

Modules in the Gauss virus have internal names that Kaspersky Lab researchers believe were chosen to pay homage to famous mathematicians and philosophers, including Johann Carl Friedrich Gauss, Kurt Godel and Joseph-Louis Lagrange.

Kaspersky Lab said it called the virus Gauss because that is the name of the most important module, which implements its data-stealing capabilities.

One of the firm’s top researchers said Gauss also contains a module known as “Godel” that may include a Stuxnet-like weapon for attacking industrial control systems.

Stuxnet, discovered in 2010, spread via USB drives and was designed to attack computers that controlled the centrifuges at a uranium enrichment facility in Natanz, Iran.

Eleven machines have been detected with the malware in the UAE in the last few weeks, Kaspersky Labs said in its report.

Here’s a video on Stuxnet: Anatomy of a Computer Virus

Direction and Motion Graphics: Patrick Clair patrickclair.com
Written by: Scott Mitchell

[tubepress video=”25118844″]

Facebook Comments