Newsletters
News & Information for Technology Purchasers NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
Home Enterprise I.T. Cloud Computing Applications Hardware More Topics...
Neustar, Inc.
Protect your website & network
using real-time information & analysis

www.neustar.biz
Security Solutions
Tame your scariest paperwork. Find Out How
Average Rating:
Rate this article:  
Stuxnet-Like Virus Detected, Intentions Unclear
Stuxnet-Like Virus Detected, Intentions Unclear

By Adam Dickter
October 19, 2011 9:55AM

    Bookmark and Share
"From a code analysis standpoint it is quite clear that Duqu's authors had access to at least some of the source code from Stuxnet," said security analyst Chet Wisniewsky of the security firm Sophos. "Whether it is the same group or what their intentions are, is hard to tell" because the Stuxnet-like Duqu can download additional components.
 



A malicious code that may have been a top-secret effort to thwart Iran's nuclear program appears to be back in business. But this time, it may not only be a threat to the global ambitions of ayatollahs.

That's the warning of software security and services firm Symantec, which announced the threat on a company blog Tuesday after a client provided samples of code that could be "the next Stuxnet." Symantec did not name the client but said it was a research lab "with strong international connections."

Trojan Horse

Duqu is a remote access Trojan, or RAT, that collects information that could be used for later attacks.

Variants of the threat, dubbed "Duqu" [pronounced dyü-kyü] because its files carry the prefix DQ, were detected as recently as Monday. Duqu appears to have been aimed at a limited number of manufacturing companies. The samples were recovered from systems in Europe and Symantec, which is based in Mountain View, Calif., confirmed that parts of the virus are nearly identical to Stuxnet, which caused mayhem for Iran's uranium enrichment program in the summer of 2010.

Other systems running Siemens industrial software were also affected, but since 60 percent of computers infected were in Iran, there was wide speculation by security specialists that it was created by American or Israeli intelligence operatives, or a collaboration of both.

Duqu's intentions are more amorphous, leaving computer security experts scrambling not just to identify and counter the virus but to decipher its goal.

"From a code analysis standpoint it is quite clear that Duqu's authors had access to at least some of the source code from Stuxnet," said senior analyst Chet Wisniewsky of the security firm Sophos. "Whether it is the same group or what their intentions are, is hard to tell. Considering that this malware can download additional components it makes it much more difficult to determine the intent than Stuxnet."

Targeting Design Documents

Symantec said Duqu is "essentially the precursor to a future Stuxnet-like attack. The threat was written by the same authors (or those that have access to the Stuxnet source code) and appears to have been created since the last Stuxnet file was recovered. Duqu's purpose is to gather intelligence data and assets from entities, such as industrial control system manufacturers, in order to more easily conduct a future attack against another third party. The attackers are looking for information such as design documents that could help them mount a future attack on an industrial control facility."

Symantec said that while the payload of Stuxnet was intended to sabotage an industrial control system, Duqu's payload is general remote access capabilities.

Symantec said that while the threat was aimed at a limited number of organizations it may well be that there are others under attack, as-yet-undetected.

In an update on Tuesday, Symantec said part of the malware had been linked to a Symantec customer in Taipei, Taiwan, and the company revoked that customer's code-signing certificate, but now believes the code was stolen and not generated for hacking purposes.
 

Tell Us What You Think
Comment:

Name:



Neustar, Inc. (NYSE: NSR) is a trusted, neutral provider of real-time information and analysis to the Internet, telecommunications, information services, financial services, retail, media and advertising sectors. Neustar applies its advanced, secure technologies in location, identification, and evaluation to help its customers promote and protect their businesses. More information is available at www.neustar.biz.


 Security Solutions
1.   Gartner Rates IT Security Companies
2.   Apple Updates Mavericks, iOS 7
3.   New Pass Codes You Can't Forget
4.   Focus on Security in New Dell Products
5.   BlackBerry BBM Boosts Security


advertisement
Gartner Rates IT Security Companies
IBM, HP, McAfee, Splunk ranked well.
Average Rating:
Apple Updates Mavericks, iOS 7
Another failed attempt by Apple?
Average Rating:
New Pass Codes You Can't Forget
Scientists debut new Facelook security.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Network Security Spotlight
Report: Chinese Hackers Hit U.S. Personnel Networks
Hackers from China broke into the computer networks of the U.S. Office of Personnel Management earlier this year with the intention of accessing the files of tens of thousands of federal employees.
 
Charges: Russian Stole Data from U.S. Restaurants, Zoo
A Russian man arrested on bank fraud and other charges hacked into computers at restaurants in Washington, hundreds of other retail businesses, and even the Phoenix Zoo, authorities say.
 
Another Month, Another IE-Focused Patch Tuesday
Microsoft rolled out 59 vulnerabilities for Internet Explorer in June. But the IE-patching party is not over yet. Redmond published six new security bulletins on Tuesday; two, critical; three, important.
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Cloud Computing | Applications | Hardware | Mobile Tech | Big Data | Communications
World Wide Web | Network Security | Data Storage | Small Business | Microsoft/Windows | Apple/Mac | Linux/Open Source | Personal Tech
Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.