ThatPainter is reader-supported. When you buy through links on our site, we may earn an affiliate commission. Learn More
Flame was a modular Windows cyber-espionage toolkit discovered in 2012—not simply a conventional virus. Kaspersky described it as a backdoor Trojan with worm-like capabilities, able to collect data such as screenshots, keystrokes, voice communications and network traffic. A remarkable part of the incident was a forged certificate that made a Flame component appear to be signed by Microsoft.
As an Amazon Associate I earn from qualifying purchases.
What is Flame malware?
Flame, also called Flamer or sKyWIper, was a sophisticated espionage toolkit. Kaspersky’s retrospective describes a backdoor Trojan with worm-like behavior: operators could direct it to spread across local networks or through removable storage, while its modular design allowed additional functions to be added. Kaspersky reported detecting 20 extension modules; that is the number found in its account, not a definitive count of every module ever created.
Among the capabilities Kaspersky reported were network-traffic analysis, screenshots, voice recording and keystroke logging. The retrospective places Flame’s development at about 2008 and its exposure in May 2012. These are historical descriptions, not evidence of current prevalence.
#1 Best Overall
How did Flame spread?
Kaspersky reported that Flame could move through local networks and removable storage when instructed by its operators. A more unusual route involved intercepting local Windows Update requests and substituting a malicious module bearing a fraudulent certificate that appeared to chain to Microsoft. This was not a compromise of all Windows Update traffic or a universal remote infection method; Microsoft’s technical account describes a certificate-spoofing attack involving man-in-the-middle conditions.
How did Flame fake a Microsoft certificate?
Microsoft said a Terminal Server Licensing service had used an older cryptographic algorithm and issued certificates with code-signing capability. Attackers exploited a weakness in that certificate infrastructure to create a fraudulent certificate that chained to a Microsoft root. That appearance of trust could let signed code be accepted across Windows versions.
CWI cryptanalyst Marc Stevens identified the method as a new variant of an MD5 chosen-prefix collision attack. In accessible terms, the cryptographic weakness let the attackers construct a certificate that appeared to have a trusted relationship to Microsoft, despite being fraudulent. Stevens described it as a new variant of a “chosen prefix collision attack” used to impersonate a legitimate Microsoft security update.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesMicrosoft invalidated the Terminal Server Licensing certificate hierarchy implicated in the attack, issued Security Advisory 2718704 and an update to block unauthorized certificates, and stopped issuing certificates from that service with code-signing ability. It moved the service to a separate root and constrained certificates to licensing rather than code signing.
Rank #3
How many computers did Flame infect?
Kaspersky Lab’s 2012 retrospective recorded about 700 Flame incidents in its own data and estimated roughly 5,000–6,000 incidents overall. These are historical estimates, not a verified count of unique computers or people affected.
Was Flame connected to Stuxnet?
Kaspersky reported that a module created on the Flame platform was used in 2009 as a propagation module for Stuxnet. The company presented this as evidence of cooperation and source-code exchange between development teams. That specific attribution should not be expanded into a claim that every operation or component associated with either malware shared a developer.
Rank #4
Is Flame malware still active?
The cited reporting covers Flame’s discovery and the 2012 response. It does not establish whether Flame or its infrastructure is active today, so a current activity claim cannot be verified from these sources. The practical lesson from the incident is the importance of secure certificate systems and trusted software-update channels, alongside prompt vendor action when a trust mechanism is compromised.
Quick Recap
Best Value
Sources
- Microsoft Security Response Center, “Microsoft releases Security Advisory 2718704,” June 3, 2012
- Microsoft Security Research & Defense, “Flame malware collision attack explained,” June 6, 2012
- Kaspersky Securelist, “Kaspersky Security Bulletin 2012. Cyber Weapons”
- Centrum Wiskunde & Informatica, “CWI cryptanalyst discovers new cryptographic attack variant in Flame spy malware,” June 7, 2012
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




