Attribution
Attributed to a sophisticated nation-state cyber-espionage operation. Kaspersky Lab established a direct code and infrastructure link to the Flame and Gauss platforms (miniFlame was codenamed 'SPE' inside Flame's original C&C servers and referenced as 'John' within Gauss configuration files), placing it inside the same 'cyber-weapon factory' as Flame, Gauss and — by extension — Stuxnet/Duqu, the toolset widely reported to be part of the US-Israel 'Operation Olympic Games' effort. Kaspersky did not formally name a sponsor state. Confidence: medium (strong technical linkage to Flame/Gauss; state sponsorship inferred, not formally confirmed by the vendor).
First seen
2012 (publicly disclosed by Kaspersky Lab in October 2012). Kaspersky identified six variants dating to 2010-2011, with analysis suggesting development may have begun as early as 2007.
Last active
2010-2011 (samples), disclosed 2012; no activity observed since. Considered historically dormant/defunct.
Motivation
Cyber-espionage — targeted intelligence collection, data theft and remote surveillance against a small, hand-picked set of high-value victims.
Attribution confidence
medium
MENA targeting
Lebanon, Palestinian Territories, Iran
Sectors
Targeted individuals / high-value espionage
Why it mattersState-sponsored / APT actor, medium confidence, documented targeting Lebanon, Palestinian Territories, Iran (Targeted individuals / high-value espionage sector).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.