Gauss is a nation-state banking-and-surveillance toolkit discovered by Kaspersky in 2012, built on the Flame platform, that uniquely targeted Lebanese banks alongside credential and browser data — assessed as a financial-intelligence operation focused on the Middle East, especially Lebanon.
Gauss was disclosed by Kaspersky Lab in August 2012 during its investigation of Flame. Kaspersky assessed with high confidence that Gauss was produced on the same platform ('Tilded'-related) as Flame and by a related nation-state actor, placing it in the U.S./Israel-attributed lineage of Stuxnet/Flame/Duqu; as with its siblings, the specific sponsor is circumstantial and officially unconfirmed, a nuance preserved here. Gauss has no MITRE Group ID (catalogued as malware).
Gauss's distinguishing feature is its financial-intelligence focus: modules designed to steal credentials for specific Lebanese banks (including Bank of Beirut, EBLF, BlomBank, ByblosBank, Credit Libanais), as well as Citibank and PayPal, alongside browser history, cookies, and system configuration data. It also carried an encrypted, still-undecrypted payload ('Godel') whose target conditions were never publicly resolved, and infected USB drives for propagation and data collection.
MENA is Gauss's core theater. Kaspersky's telemetry concentrated infections overwhelmingly in Lebanon, followed by Israel and the Palestinian Territories, with additional Middle Eastern victims — an unusual banking-surveillance mission suggesting interest in monitoring financial flows in the region, possibly tied to tracking funding networks.
Gauss command-and-control went dormant shortly after discovery in 2012 and no further activity has been reported; it is assessed as retired. It is included as an attribution-sensitive Flame-family toolkit with a distinctly Lebanese/MENA financial-intelligence mission, flagged circumstantial on sponsor.