Gauss is a Windows malware platform associated with the Flame ecosystem and widely regarded as a nation-state cyber-espionage tool with banking-trojan functionality. It was publicly identified in 2012 and has been linked by code similarity and shared development lineage to Flame and MiniFlame, with broader reporting also placing it in the same developer ecosystem as Stuxnet and Duqu. Gauss was used in espionage operations concentrated in the Middle East, with especially heavy victimization reported in Lebanon and additional activity in Israel and the Palestinian territories.
Gauss combines surveillance, credential and financial-data theft, and selective payload deployment. Its known modules were designed to intercept information related to online banking activity, including data associated with Lebanese financial institutions. Beyond banking theft, Gauss collected system and user information consistent with reconnaissance and intelligence gathering. It also implemented an unusual target-validation mechanism in which reconnaissance data from a victim environment was used to derive a decryption key for a protected payload, allowing that payload to activate only on specifically intended machines. This environmental keying approach limited exposure of full capabilities outside designated targets and complicated analysis.
Gauss also had air-gap-relevant tradecraft. Like Flame, Stuxnet, and MiniFlame, it used the Windows shortcut vulnerability CVE-2010-2568 to gain execution from USB media, and it has been documented as part of broader efforts to bridge disconnected environments. In air-gapped scenarios, Gauss gathered host-specific information that could be used to unlock a payload for a uniquely targeted system. This behavior aligns with long-duration espionage operations focused on careful victim selection rather than indiscriminate deployment.
The malware is best characterized as an infostealer with espionage-oriented modular design. Its operational profile reflects state-grade development priorities: stealth, selective activation, banking-data interception, and intelligence collection against Windows systems in strategically relevant regional targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The most famous vulnerability is without a doubt CVE-2010-2568, aka the “Stuxnet LNK exploit”. ... Fanny had used that exploit even before Stuxnet ... Flame, Gauss and miniFlame continued to use it afterwards. | Gauss ... one of the purposes behind the approach of slowly mapping and surveying the systems in the air-gapped network: with the information collected, the attackers are able to encrypt a payload that only can be decrypted on specific computers.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
First from Flame to Mini-Flame, it’s likely predecessor, and then to Gauss, considered a more widespread successor or perhaps a side operation.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
Malicious LNK files are usually used as the exploit to trigger a vulnerability in old components of Windows, such as the Windows Shell, that allow the malware to get remote code execution with no user action required other than viewing the LNK file in Windows Explorer.
Obtained host network configuration and connectivity capability, limited attempt to get network topology (using ping and tracert)
Frameworks gather information such as computer name, username, domain name, list of running processes
Frameworks gather information such as computer name, username, domain name, list of running processes, listing of files in directories, drives and network shares, as well as network configuration information
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malicious program identified through code similarity as being from the same group behind Flame.
A malware family related to Flame, noted here for using .ocx-named modules, XOR encryption, and USB-based data container handling via .thumbs.db.
A modular espionage malware family discussed as a more widespread successor or side operation related to Flame, notable for an encrypted payload that had not been cracked.
A modular malware family discussed as a more widespread successor or side operation related to Flame, notable in the article for its lore around a never-cracked encrypted payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.