Flame is a large, modular cyber-espionage toolkit exposed by Kaspersky, CrySyS Lab, and Iran's CERT in 2012, assessed as a nation-state operation sharing lineage with Stuxnet, that conducted wide-ranging surveillance across Iran and the Middle East — collecting documents, audio, screenshots, and Bluetooth-proximate data.
Flame (also Flamer / sKyWIper) was disclosed in May 2012 by Kaspersky Lab, Hungary's CrySyS Lab, and Iran's Maher CERT. Unusually large and modular for its era, it is widely assessed as a state-sponsored espionage platform; researchers later established a cryptographic and code link to Stuxnet, tying Flame to the same U.S./Israel-attributed operational lineage. Attribution is high confidence on sophistication and Western state sponsorship but remains officially unconfirmed and circumstantial on the exact agency — a nuance preserved here; Flame has no MITRE Group ID (it is catalogued as malware).
Flame's tradecraft was defined by breadth of collection: modular plugins for keylogging, screen capture, microphone audio recording, Bluetooth device scanning, network traffic sniffing, and document theft, with data exfiltrated to a sprawling C2 infrastructure. It used a forged Microsoft certificate (via an MD5 chosen-prefix collision) to sign components and spread, and included a kill/removal module ('browse32') to erase itself once exposed.
MENA is Flame's defining theater. Kaspersky's telemetry concentrated victims in Iran, followed by Israel/Palestinian Territories, Sudan, Syria, Lebanon, Saudi Arabia, and Egypt, spanning government, educational, and individual targets — collection aligned with intelligence preparation around the Iranian nuclear program and regional tensions.
Following exposure in mid-2012 the operators triggered Flame's self-removal, and no new Flame activity has been reported since; it is assessed as retired. It is included as a landmark attribution-sensitive nation-state espionage toolkit with heavy MENA victimology, flagged circumstantial on sponsor.