The search had been for something else. After malware tried to wipe data at Iran's oil ministry (April 2012), the International Telecommunication Union asked Kaspersky Lab to find it. No sample of the wiper turned up; the hunt found instead an unknown program, which Kaspersky named after one of its modules, Flame, the part that attacked and infected new machines. Kaspersky published on 28 May 2012, and not alone. MAHER, Iran's national CERT, called the program Flamer, said it had given selected Iranian organisations a detection tool at the beginning of May, and suggested that recent mass data losses in Iran might be one module's work. In Budapest the CrySyS laboratory, alerted that month, published under a third name, sKyWIper, after ~KWI, a name used for its temporary files.
The toolkit was vast for its day: nearly twenty megabytes with every module installed, about twenty times the size of Stuxnet, written partly in the Lua scripting language, its findings filed in SQLite databases. It could turn on a microphone and record the room, take screenshots while instant-messaging programs were open, log keystrokes and sniff network traffic. A module Kaspersky called BeetleJuice listed the Bluetooth devices within range and could make the infected computer discoverable, a beacon advertising the malware's status. Another planted backdoor accounts named HelpAssistant across a network domain. It spread by USB stick and through a print-spooler flaw Stuxnet had used, and had reached fully patched Windows 7 machines. CrySyS called it the most sophisticated malware it had met, arguably the most complex ever found.
Its age and reach were estimates, and they differed. Kaspersky had it in the wild since February or March 2010 at least, and said no security software had detected it; MAHER said forty-three anti-virus products it tested had missed it. CrySyS suggested five to eight years, perhaps more: the file name of its main component had been logged by Webroot's user community in Europe on 5 December 2007, in the United Arab Emirates in April 2008 and in Iran in March 2010, without raising an alarm. Kaspersky's figures put Iran far ahead, at 189 machines or more, then Israel and the Palestinian territories, Sudan, Syria, Lebanon, Saudi Arabia and Egypt; the victims ran from individuals to educational institutions and state-related organisations, about a thousand machines by its first estimate.
Kaspersky was sure a nation state had paid for it, and said nothing in the code pointed to which. On 29 May Israel's vice prime minister, Moshe Ya'alon, told Army Radio that whoever took Iran's threat seriously was likely to take various steps against it, this kind among them; a spokesman later denied he had implied responsibility. The command servers went offline as soon as Flame was exposed, and in June a newspaper citing Western officials placed Flame inside an American and Israeli programme. In September Kaspersky, with Symantec and others, showed what one server had held: a control platform begun as early as December 2006, dressed as a content-management system, taking in more than five gigabytes a week from over five thousand machines.
The right answers
WHMCS, which made billing and support software for web hosts, lost its own server on Monday 21 May 2012, and said that no flaw in its software had been used. Someone had passed as its founder, Matt Pugh, with the company's web host, answered the host's verification questions, changed the account's email address and had the access details sent there. The group UGNazi then published the site's files and database — 1.7 gigabytes, by Brian Krebs's account, with usernames, passwords and card details for about half a million customers — took over the company's Twitter account, deleted the server's files and flooded the site when it came back. The card numbers were encrypted; The Register relayed reports, unconfirmed by the company, that the key to them had been left in clear text on the server and leaked too. UGNazi said WHMCS served scam sites and had ignored its warnings, and Pugh put the matter in the FBI's hands. On 24 May Krebs reported that hackers had for four months been selling underground what they claimed was an unpatched flaw in the software itself. On 26 June two of the group's members were among those arrested in Operation Card Shop, an FBI investigation into card fraud.
Updates nobody asked for
On 8 May 2012 the FBI and its Internet Crime Complaint Center warned travellers abroad about hotel rooms: laptops had been infected as their owners set up the room's internet connection, when a pop-up window offered an update to a widely used software product and accepting it installed malware. The bureau advised taking updates abroad only from the vendor's own website; Brian Krebs's shorter rule was to install nothing one had not gone looking for. Kaspersky Lab would later describe Darkhotel, which had followed executives onto hotel networks in Asia with false updates since at least 2007 (November 2014). A signature was meant to settle whether an update was genuine. On 23 May Yahoo launched Axis, a search tool shipped as an app and as extensions for desktop browsers; by the next day Nik Cubrilovic, an Australian entrepreneur, had found inside the Chrome extension's package the private key Yahoo had signed it with. Anyone holding it could build an extension Chrome would accept as Yahoo's and, on a network they controlled, slip it in as a routine update. Yahoo apologised and replaced the extension; it retired Axis in June 2013.
Thirty-six hours and a list of words
Statutory motions were rare, P. Rajeeve reminded the Rajya Sabha on Thursday 17 May 2012 as he moved one. The CPI(M) member from Kerala asked the House to annul the Information Technology (Intermediaries Guidelines) Rules, 2011, and the Lok Sabha to concur. The rules tied an intermediary's protection from liability to due diligence, including acting within thirty-six hours on any affected person's complaint about content in a list of undefined terms, grossly harmful, harassing, blasphemous and defamatory among them. That, he argued, was private censorship the IT Act did not allow, with no hearing for whoever had posted the content; even MTNL, which connected members' iPads in the House, was an intermediary. Arun Jaitley, Leader of the Opposition, accepted the design but not the words: defamation admitted truth as a defence, and taking down everything defamatory would leave a very boring internet.
Kapil Sibal, the minister, said the government stood for neither censorship nor the regulation of speech; sites not registered in India answered to no Indian law when the state asked about a terrorist attack or a drug trade; an intermediary could still refuse. Pressed by Jaitley, he undertook to take members' written objections to specific words to a meeting of members, industry and other stakeholders, and to act on whatever consensus it reached. The motion was negatived by voice vote, the same week providers were blocking whole websites under a court order (June 2012). The ministry later said thirty-six hours meant acknowledging a complaint and starting to act on it; on 24 March 2015 the Supreme Court confined the duty to court orders and government notices, on grounds the Constitution permits, and new rules replaced these in February 2021.
Google's Knowledge Graph and machine-marked essays
On 16 May 2012 Amit Singhal, Google's senior vice-president of engineering, introduced the Knowledge Graph, a model of real-world entities and the links between them — "things, not strings", as he put it — and Google began showing American users searching in English a panel of facts beside the results. It put the graph at more than 500 million objects and more than 3.5 billion facts and relationships, drawn partly from Wikipedia, the CIA World Factbook and Freebase, which came with its 2010 purchase of Metaweb; a search for the Taj Mahal now separated the monument from the musician. By 2020 Google counted more than 500 billion facts about five billion entities. Earlier, on 9 May, the Hewlett Foundation had split $100,000 among three teams in a Kaggle contest for software that marked state-test essays the way human graders had; a British particle physicist, a National Weather Service data analyst and a German graduate student took the $60,000 first prize. Critics said such programs judged mainly structure and grammar, not whether an argument held.
Microsoft expels a partner over a leak
Microsoft patched a Remote Desktop flaw, in bulletin MS12-020, on 13 March 2012 and expected working attack code within thirty days. Within three days a program that crashed unpatched machines appeared on a Chinese download site. Luigi Auriemma, who found the flaw, recognised in it the packet he had modified by hand for the Zero Day Initiative, which had reported the flaw to Microsoft; a debugging string, MSRC11678, pointed to the company's own security response centre. On 16 March Microsoft said the details appeared to match what it had shared through its Active Protections Program, which briefed security vendors shortly before each patch. On 3 May 2012 Yunsun Wee of its Trustworthy Computing group said Hangzhou DPTech Technologies, a Chinese firewall maker, had "breached our non-disclosure agreement" and been removed. He did not explain the finding; DPTech did not respond to reporters. After the SharePoint attacks of July 2025, Microsoft, without saying what part, if any, the programme had played, stopped sending proof-of-concept code to companies obliged to report flaws to their governments, including China's.
⏳ Time capsule — May 2012
- On 2 May a pastel version of Edvard Munch's The Scream, made in 1895 and sold by the Norwegian businessman Petter Olsen, fetched $119.9 million, with the buyer's premium, at Sotheby's in New York after more than twelve minutes of bidding, then a record for a work of art at auction.
- On 18 May Facebook's shares began trading on Nasdaq, priced the day before at $38 to raise $16 billion and value the company at $104 billion; a fault at the exchange held up the start until 11.30 in the morning, and the shares closed at $38.23.
- On 25 May the International Space Station's robotic arm, worked by the astronaut Don Pettit, caught SpaceX's Dragon, which was then berthed to the Harmony module — the first commercial spacecraft to berth with another in orbit; it splashed down in the Pacific on 31 May.
- On 30 May, in Moscow, Viswanathan Anand retained the world chess title, his third successive defence, beating Boris Gelfand of Israel 2½–1½ in rapid games after their twelve classical games had finished 6–6.
Found while looking for something else
Flame's lesson was how long a patient program could go unremarked. Pieces of it had been seen, and, CrySyS believed, uploaded to analysis sites, years before anyone looked closely, and Kaspersky found it only because a UN agency had asked it to look for something else. The platform outlived its name: Gauss, built on it, surfaced in August, and in April 2019 two researchers at Chronicle, Juan Andrés Guerrero-Saade and Silas Cutler, described a Flame 2.0, built from the original source code and probably in use from 2014 to 2016, parts of which they still could not decode. The same modular patience ran through Regin, taken apart in public in November 2014. No government has acknowledged building Flame.
May's smaller stories ended in more familiar places. WHMCS lost its server to a set of verification questions, the kind of check callers went on talking past: at Apple and Amazon in August, and, by the attackers' own account, at a casino company's help desk in September 2023. Yahoo's key was caught within a day by someone who looked inside the package; a compromised build server at Adobe in September showed the other way a signature could mislead. In India the rules Jaitley wanted reworded stayed in force until February 2021, and their successors, amended since, still set platforms deadlines by the hour. The duty to report a breach came by direction in 2022, the data protection statute in 2023.