miniFlame (aka SPE, and 'John' in Gauss) is a small, high-precision cyber-espionage module discovered and analyzed by Kaspersky Lab in 2012. Unlike the broadly distributed Flame (~5,000-6,000 infections) and Gauss (~10,000 infections), miniFlame was a surgical second-stage tool: Kaspersky estimated only 50-60 total infections worldwide. It functions as a standalone backdoor that can also operate as a plug-in for both Flame and Gauss, providing attackers direct remote control, data theft, screenshot capture and file exfiltration on already-compromised, specially selected machines.
In July 2012, while analyzing Gauss, Kaspersky Lab's Global Research and Analysis Team identified an additional module codenamed 'John' and found references to the same module in Flame's configuration files. Subsequent analysis of Flame's command-and-control servers in September 2012 revealed that this module — codenamed 'SPE' in Flame's C&C code — was in fact a separate malicious program that could also be used as a plug-in by both Gauss and Flame. Kaspersky publicly disclosed it as 'miniFlame' in October 2012 (Securelist: 'miniFlame aka SPE: Elvis and his friends'). Six variants were identified, dating to 2010-2011, with evidence the codebase may date back to 2007. The design pattern was staged: Flame and Gauss were used for broad reconnaissance to identify the most valuable compromised systems, after which miniFlame was deployed to those select targets for direct control and deep surveillance. Kaspersky put total infections at roughly 50-60, with the two main victim concentrations in Lebanon and Iran; variant '4.50' clustered in Lebanon and the Palestinian territories, with other variants seen in Iran and elsewhere in the region. The toolset is historical (2012-era) and long defunct. MENA relevance: CONFIRMED/REAL — Kaspersky's primary reporting explicitly names Lebanon, the Palestinian territories and Iran among the victim geographies, matching the RaqibCTI country tags (Lebanon, Palestinian Territories, Iran).