infoTECH Feature

October 19, 2011

New Duqu Worm Has Infected Computers Worldwide, May Be Stuxnet 2.0

It appears that a new Duqu worm strongly resembles the Stuxnet malware, according to Symantec (News - Alert) researchers.

Symantec says the new worm could “attack and cripple industrial control systems, much like Stuxnet did,” according to a report from eWeek.

Symantec researchers first saw Duqu on Oct. 14. Symantec has found that industrial computers "around the globe" have been infected, eWeek said.

Duqu worm was described as a “remote access Trojan (RAT),” according to media reports.

Symantec suspects the new worm “was either created by the same team or by another group with access to the Stuxnet source code,” researchers were quoted by eWeek.

“Both viruses use similar encryption keys and techniques, injection code and fraudulent digital certificates, which had been issued to companies in Taiwan. The digital certificate keys appear to be real, which also make the programs look legitimate,”eWeek said.

However, while Stuxnet was “designed to attack a very specific type of computer system” Duqu “does not appear to have a clear target,” eWeek said.

Stuxnet malware was blamed for compromising systems at Iran's Natanz nuclear facility, eWeek said. “Observers believe the malware set Iran's nuclear program back years,” eWeek adds. Israel was suspected as playing a key role with the Stuxnet attack on the Iranian nuclear facility, TMCnet said.

"Duqu is essentially the precursor to a future Stuxnet-like attack," Symantec researchers wrote on a blog. In addition, given its overall sophistication, a government is likely the creator of Duqu, eWeek said.

Also, Duqu could be used in “intelligence-gathering from industrial control system manufacturers,” Symantec speculates. The use of Duqu may be a “precursor to a larger, more comprehensive attack,” eWeek adds.

“At the moment, Duqu only creates a backdoor on infected systems and connects with a command-and-control server somewhere in India, according to Symantec. The backdoor is open precisely for 36 days, after which the malware self-destructs,” eWeek adds.

In his analysis, Bill Roth, CMO of LogLogic, told eWeek that Duqu "is Stuxnet, retrofitted for general remote access."

It was also reported that the worm was named "Duqu" because it creates files with prefix “~DQ”.

“Duqu's purpose is to gather intelligence data and assets from entities, such as industrial control system manufacturers, in order to more easily conduct a future attack against another third party. The attackers are looking for information such as design documents that could help them mount a future attack on an industrial control facility,” Symantec reported.


Ed Silverstein is a TMCnet contributor. To read more of his articles, please visit his columnist page.

Edited by Stefanie Mosca
FOLLOW US

Subscribe to InfoTECH Spotlight eNews

InfoTECH Spotlight eNews delivers the latest news impacting technology in the IT industry each week. Sign up to receive FREE breaking news today!
FREE eNewsletter

infoTECH Whitepapers