MiniFlame is a Windows espionage malware platform associated with the broader Flame and Gauss ecosystem and assessed as part of a nation-state cyberespionage toolset focused on covert intelligence collection. It has been described as a likely predecessor or closely related companion to Flame, with code-similarity links to Gauss and operational overlap within the same malware cluster. MiniFlame has also been identified in counter-intrusion signature sets alongside Flame, reflecting its recognition as a distinct but related component.
MiniFlame was used for reconnaissance and espionage on already selected targets rather than broad disruptive activity. Reported behavior includes awareness of removable-media artifacts and searching USB drives for specific files, indicating support for offline collection workflows and operation in environments where USB devices were used to bridge segmented or air-gapped systems. Like Flame and Gauss, MiniFlame is documented as using USB-based propagation or execution mechanisms associated with the Stuxnet LNK vulnerability, enabling code execution from removable media on Windows systems.
Within the air-gap intrusion landscape, MiniFlame is one of the known Windows-focused frameworks that used USB drives as the physical medium for movement of malware or stolen data. Its inclusion among long-running espionage frameworks targeting isolated environments places it in the class of highly selective intelligence tools rather than commodity malware. Public reporting does not firmly attribute MiniFlame to a specific actor in the cited material, but it is consistently linked technically and operationally to the Flame ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The most famous vulnerability is without a doubt CVE-2010-2568, aka the “Stuxnet LNK exploit”. ... Fanny had used that exploit even before Stuxnet ... Flame, Gauss and miniFlame continued to use it afterwards. | IdentityKit #5: miniFlame ... Perform reconnaissance and espionage against unknown entities ...
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Among them, two signatures for Flame (SIG9 and SIG16) as well as a signature for its likely predecessor, Miniflame (SIG10).
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Malicious LNK files are usually used as the exploit to trigger a vulnerability in old components of Windows, such as the Windows Shell, that allow the malware to get remote code execution with no user action required other than viewing the LNK file in Windows Explorer.
The tools ... check for the existence of specific files, windows registry entries ... For example, SIG2 includes System\CurrentControlSet\Control\CrashImage and SIG23 includes software\microsoft\NetWin.
Frameworks gather information such as computer name, username, domain name, list of running processes
Frameworks gather information such as computer name, username, domain name, list of running processes, listing of files in directories, drives and network shares, as well as network configuration information
They check for the existence of specific files, windows registry entries, and other signs ... For example, this script looks for the existence of an actual file “winver32.exe” in the very specific $docsandsettings\\$subkey\\Application Data\\winver32.exe path.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malicious program identified through code similarity as being from the same group behind Flame.
A malware related to Flame/Gauss that searched USB sticks for .thumbs.db containers, showing conceptual similarity to Agent.BTZ-style removable-media data handling.
A likely predecessor to Flame, described as relatively simple compared with Flame and Gauss, and part of the same espionage malware lineage.
A likely predecessor to Flame, discussed as part of the same espionage lineage and included in historical malware signatures tied to the broader cluster under study.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.