Stuxnet, Flame...Gauss: New spy virus found in Middle East

Published time: August 09, 2012 16:17
Edited time: August 09, 2012 20:38
Kaspersky Lab has found a new Trojan virus which has been spying on hundreds of users in the Middle East (image from http://www.securelist.com)

A new virus dubbed Gauss has attacked computers in the Middle East spying on financial transactions, emails and picking passwords to all kind of pages. The virus resembles Stuxnet and Flame malware which was used to target Iran, Kaspersky Lab says.

­Gauss has infected hundreds of personal computers across the Middle East – most of them in Lebanon, but also in Israel and Palestinian territories. Kaspersky Lab has classified the virus, named after one of its major components, as “a cyber-espionage toolkit”.

The malicious malware spies on transactions in banking systems and steals passwords and credentials to social networks, emails and instant messaging accounts. It can also collect system configurations.

Though Gauss seems to be specifically designed for several Lebanese online banking systems, it can also go after Citibank and PayPal users.

­

Gauss can spread through USB drives using the same system vulnerability as previously unleashed Flame virus (image from http://www.securelist.com)
Gauss can spread through USB drives using the same system vulnerability as previously unleashed Flame virus (image from http://www.securelist.com)

­

It is not immediately clear who may be behind the new Trojan virus, but Kaspersky Lab says the “nation-state sponsored” toolkit has features characteristic of Flame, DuQu and Stuxnet malware, which targeted machines in Iran.

"After looking at Stuxnet, DuQu and Flame, we can say with a high degree of certainty that Gauss comes from the same 'factory' or 'factories,'" Kaspersky Lab said in their report on Thursday. "All these attack toolkits represent the high end of nation-state-sponsored cyber-espionage and cyber war operations."

The researchers cannot say whether Gauss was meant to simply spy on account transactions, or to steal money from targets. But given the high probability of a nation-state actor behind it, the virus may be a counterintelligence tool, which could be used to trace funding of various groups or individuals.

­

Gauss has attacked over 2,500 personal computers in the Middle East. Only one attack has so far been reported in Iran (image from http://www.securelist.com)
Gauss has attacked over 2,500 personal computers in the Middle East. Only one attack has so far been reported in Iran (image from http://www.securelist.com)

­

The virus is yet to be fully exposed, as the Moscow-based internet security company is still trying to crack its payload, a section that sends and receives instructions from an outside source once it has infiltrated a system. The company is asking for assistance from any cryptographers since the payload is highly encrypted and its purposes remain unclear.

The virus was first spotted in June this year while Kaspersky Lab was looking for variants of Flame. Gauss appears to have been most active from May to July 2012, until its control and command infrastructure stopped functioning. Now the virus is in a dormant state.

Still, the malware, apparently created back in 2011, managed to spread much farther than Flame, which attacked around 700 PCs across the Middle East this spring.

Flame and Stuxnet are widely speculated to have been ordered by the US and Israel to hit Iran’s nuclear program. Western officials gave a tentative confirmation the CIA, the National Security Agency and the Israeli military were all involved in developing the Flame spying toolkit.

As for the Stuxnet attack, which in 2010 damaged uranium enrichment centrifuges in Iran, Washington has so far declined to comment on if it was behind the sabotage.

Now Gauss, which shares parts of its code with Flame, appears to add to the US and Israel’s presumed cyber arsenals.

­

Modules in the Gauss virus have internal names that Kaspersky Lab researchers believe were chosen to pay homage to famous mathematicians and philosophers, including Johann Carl Friedrich Gauss, Kurt Godel and Joseph-Louis Lagrange (image from http://www.securelist.com)
Modules in the Gauss virus have internal names that Kaspersky Lab researchers believe were chosen to pay homage to famous mathematicians and philosophers, including Johann Carl Friedrich Gauss, Kurt Godel and Joseph-Louis Lagrange (image from http://www.securelist.com)

Comments (20)

Michael (unregistered) 14.08.2012 06:11

I forgot to say, a state sponsored virus most likely mean that the programmer who used thing like Xor 0xACDC was probably hating that music! My bet is that it was a fan of Beethoven but opted for rock music to hide his trace.

There is no place for this kind of emothion on a state sponsored program. My two cents bet.

0

Undo

Michael (unregistered) 14.08.2012 06:06

First I have to apologise for my orthographic and syntatic fault on my previous post. (should it end up being showed up)

@Rin: I don't know I you saw that microsoft video about how stuxtnet performed its exploits. Should linux have the same unsafe "functionality" built-in then it would not be much less vulnerable than windows, though both operating systems have their weakness. Just make a search on youtube for 'The Stuxnet Worm analysis - Microsoft report', it's a 59minutes video.

By the way, Linux Torvald itself said in 1996 '…the Linux philosophy is "laugh in the face of danger". Oops. Wrong one. "Do it yourself". That's it.'

One huge advantage when you have the source code (government have the source code of windows) is that you can completely remove unnecessary features, and have virtually infinite hardening possiblity, you can go as far as auditing the source code; though in the real world it induce a cost. Anyway if I am in need of a secure OS I would more look for Unix os like Solaris or OpenBSD. Or even better, Integrity.

0

Undo

Michael (unregistered) 14.08.2012 05:46

INTERDIMENSIONALBEIN G (unregistered) wrote in #14
Gauss, if is not a measleading name, might also mean that there is a French conexión in this plot. _________
You are very naive to believe that a nation sponsored virus would leave such trace behind him. The french? where is the Poincare module, and the Galois? The latter would have a significant meaning since (by hoping I picked the right name) mathematicians tooks hundreeds of years to start understanding what they could do with his 'group theory'.
And I got to ask the same question again, where is the Euler modules? The creators had no taste for mathematics. :)
Back to the nation-sponsored viruses, it's clear that they did not used all the sauce available, they could have used completely new cryptography, non-standard compression algorithm, and used rc-4 instead of a mere 0xACDC Xor for encrypting mos data. I exactly mean what I want to mean: they used the minimal that is good enough to get the job done. Like doing md5sum -an algorithm broken many time even by flame- thousands of times of a directory, then some transformation for generating a key is not using the best cryptography availabe, but "good enough" to avoid its code analysed. For comparison, a worm named simile was relying on a genetic algorithm to decrypt itself, alone and without the key. Should that pat being choosen, along with some time-sensitive transformation, it would be hundreed of times worst than rc-4, which is relatively old; they could have simply used an enigma-based algorithm for most data, I would have challenged cryptanalist for a while, that's my definition of a "good enough".

0

Undo

View all comments (20)
Add comment

By posting your comment, you agree to abide by our Posting rules

Log in to comment in full, or comment anonymously under character-limit restriction.

100 Text

– required fields

Register or

Name

Password

Show password

Register

or Register

Request a new password

Send

or Register

To complete a registration check
your Email:

or Register

A password has been sent to your email address

Edit profile

Name

New password

Retype new password

Current password

Save

Cancel

Follow us