Skip to content

Hide Navigation Hide TOC

Flame - S0143 (ff6840c9-4c87-4d07-bbb6-9f50aa33d498)

Flame is a sophisticated toolkit that has been used to collect information since at least 2010, largely targeting Middle East countries. (Citation: Kaspersky Flame)

Cluster A Galaxy A Cluster B Galaxy B Level
Exploitation of Remote Services - T1210 (9db0cf3a-a3c9-4012-8268-123b9db6fd82) Attack Pattern Flame - S0143 (ff6840c9-4c87-4d07-bbb6-9f50aa33d498) Malware 1
Flame - S0143 (ff6840c9-4c87-4d07-bbb6-9f50aa33d498) Malware Exfiltration Over Bluetooth - T1011.001 (613d08bc-e8f4-4791-80b0-c8b974340dfd) Attack Pattern 1
Flame - S0143 (ff6840c9-4c87-4d07-bbb6-9f50aa33d498) Malware Replication Through Removable Media - T1091 (3b744087-9945-4a6f-91e8-9dbceda417a4) Attack Pattern 1
Flame - S0143 (ff6840c9-4c87-4d07-bbb6-9f50aa33d498) Malware Rundll32 - T1218.011 (045d0922-2310-4e60-b5e4-3302302cb3c5) Attack Pattern 1
Flame - S0143 (ff6840c9-4c87-4d07-bbb6-9f50aa33d498) Malware Audio Capture - T1123 (1035cdf2-3e5f-446f-a7a7-e8f6d7925967) Attack Pattern 1
Flame - S0143 (ff6840c9-4c87-4d07-bbb6-9f50aa33d498) Malware Screen Capture - T1113 (0259baeb-9f63-4c69-bf10-eb038c390688) Attack Pattern 1
Flame - S0143 (ff6840c9-4c87-4d07-bbb6-9f50aa33d498) Malware Flame (d7963066-62ed-4494-9b8c-4b8b691a7c82) Tool 1
Flame - S0143 (ff6840c9-4c87-4d07-bbb6-9f50aa33d498) Malware Security Software Discovery - T1518.001 (cba37adb-d6fb-4610-b069-dd04c0643384) Attack Pattern 1
Flame - S0143 (ff6840c9-4c87-4d07-bbb6-9f50aa33d498) Malware Authentication Package - T1547.002 (b8cfed42-6a8a-4989-ad72-541af74475ec) Attack Pattern 1
Flame - S0143 (ff6840c9-4c87-4d07-bbb6-9f50aa33d498) Malware Local Account - T1136.001 (635cbe30-392d-4e27-978e-66774357c762) Attack Pattern 1
Exfiltration Over Other Network Medium - T1011 (51ea26b1-ff1e-4faa-b1a0-1114cd298c87) Attack Pattern Exfiltration Over Bluetooth - T1011.001 (613d08bc-e8f4-4791-80b0-c8b974340dfd) Attack Pattern 2
Rundll32 - T1218.011 (045d0922-2310-4e60-b5e4-3302302cb3c5) Attack Pattern System Binary Proxy Execution - T1218 (457c7820-d331-465a-915e-42f85500ccc4) Attack Pattern 2
Flame (d7963066-62ed-4494-9b8c-4b8b691a7c82) Tool Flame (c40dbede-490f-4df4-a242-a2461e3cfc4e) Malpedia 2
Software Discovery - T1518 (e3b6daca-e963-4a69-aee6-ed4fd653ad58) Attack Pattern Security Software Discovery - T1518.001 (cba37adb-d6fb-4610-b069-dd04c0643384) Attack Pattern 2
Boot or Logon Autostart Execution - T1547 (1ecb2399-e8ba-4f6b-8ba7-5c27d49405cf) Attack Pattern Authentication Package - T1547.002 (b8cfed42-6a8a-4989-ad72-541af74475ec) Attack Pattern 2
Create Account - T1136 (e01be9c5-e763-4caf-aeb7-000b416aef67) Attack Pattern Local Account - T1136.001 (635cbe30-392d-4e27-978e-66774357c762) Attack Pattern 2