Stuxnet team returns with Duqu
By Tom Brewster,
The team behind the most sophisticated piece of malware ever seen has returned with some fresh malicious software.
Stuxnet creators have used much of the same code for their new creation, known as Duqu, which has grabbed the attention of security researchers after an unnamed independent team detected it.
However, Duqu is not as sophisticated as Stuxnet and is not targeting the same SCADA systems used in power plants.
The attackers are looking for information such as design documents that could help them mount a future attack on an industrial control facility.
Instead, Duqu has been used to acquire information in the lead-up to another Stuxnet-esque attack in the future, researchers have suggested.
A small number of organisations have been hit, including some in the manufacturing of industrial control systems.
“The attackers are looking for information such as design documents that could help them mount a future attack on an industrial control facility,” a blog post from Symantec read.
“Our telemetry shows the threat was highly targeted toward a limited number of organisations for their specific assets. However, it’s possible that other attacks are being conducted against other organisations in a similar manner with currently undetected variants.”
Attacks using Duqu could stretch back as far as December 2010. The malware has been used to download a separate information stealer onto systems. That info-stealer was able to pilfer data in a variety of ways, including keystroke logging, before sending it off to a command and control centre in India inside an encrypted file.
The malware was programmed to run for 36 days before removing itself from systems.
Stuxnet similarities
Security researchers across the board have been fairly certain Duqu was created by the same team behind Stuxnet, even though there is no direct proof.
“They had to have access to the original source code, which only the creators of Stuxnet have. There are various decompilations available online. Those would not do,” Mikko Hypponen, chief research officer at F-Secure, told IT Pro.
“It's perfectly possible they [the team behind Stuxnet] did a similar information-cathering phase in 2008 or 2009 for the original Stuxnet and we just missed it.”
Aside from the code similarities, Duqu's driver files are signed with certificates apparently stolen from a Taiwanese company, as were Stuxnet’s.
Certificates were stolen from RealTek and JMicron in the case of Stuxnet, whereas in Duqu only one was compromised - C-Media Electronics Incorporation.
In recent cases, certificate authorities have been compromised so hackers could issue fraudulent certificates, as was seen with the now-defunct CA DigiNotar. However, the certificate used to sign Duqu appears to have been stolen somehow, even though McAfee’s analysis suggested otherwise.
“Symantec has known that some of the malware files associated with the W32.Duqu threat were signed with private keys associated with a code signing certificate issued to a Symantec customer,” the security giant said today.
“Symantec revoked the customer certificate in question on 14 October 2011. Our investigation into the key’s usage leads us to the conclusion that the private key used for signing Duqu was stolen, and not fraudulently generated for the purpose of this malware.”
McAfee said Duqu was being used in areas occupied by “Canis Aureus,” the Golden Jackal. See below for a map outlining where these areas are:
(Source: Wikipedia)
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Security Analysis & Insight
What is your password worth?
Would you be tempted to sell off company passwords for a fee? If not, seems like you're in the minority, acccording to research.
- Macs under attack?
- Intel: security inside
- Are you spending too much on IT security?
- Does the government want to snoop on your data?
- Eurocrats versus the cyber criminals
- The truth about spam
- Google and privacy: What’s the problem?
- Q&A: Symantec’s CISO on the source code hack
- RSA: Back from the breach?
Latest Security Reviews
Check Point 2210 Appliance review
Rating: ![]()
advertisement
Most popular
- UK regulator shuts down Angry Birds scam
- Apple iPad 3 vs iPad 2 head-to-head review
- IBM bans use of Siri on iPhones
- Chromebooks: What's gone wrong?
- HP plans massive job cuts
- EMC World 2012: Tucci declares Documentum is here to stay
- Dell EqualLogic PS6100XS review
- Macs and Android under malware threat
- RIM loses its head of sales
- Local fibre broadband needs common standards
Latest News Videos in Security
IT PRO Podcast: Are UK data protection laws flawed?
We bring in two experts to talk about the problems with UK data protection law and the way it is managed.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.






Duqu virus
The computer malware Stuxnet has been tough for many computer experts to determine. In 2010, it infected nuclear control systems in Iran. Industrial control computers in Europe have been infected with a brand new malware. The Duqu virus doesn't appear to have direct influence, but mines for information that could be used for further attacks. The big news is <a title="Duqu virus uses Stuxnet DNA to mine industrial data" href="http://www.newsytype.com/12970-duqu-virus-stuxnet/">Duqu virus uses Stuxnet DNA to mine industrial data</a> .
By Wegen on Friday Oct 21