Information Age: News, analysis & insight for IT & business leaders

Stuxnet lookalike targets European companies

19 October 2011  

Newly-detected Duqu worm is designed to steal technical documents of industrial control systems, possibly to find weaknesses against cyber attack

A virus has been discovered on computer systems in Europe that is similar to Stuxnet, the worm found on Iranian nuclear control systems last year.

Duqu, which was detetected by a research lab with links to security software vendor Symantec, is designed to gather intelligence and assets from organisations including as industrial control system manufacturers, possibly in order to detect weaknesses against cyber attack.

"The attackers are looking for information such as design documents that could help them mount a future attack on an industrial control facility," the Symantec blog post said.

Duqu uses fake image files to steal information from compromised systems and sent it to a command and control server that is still operational, according to Symantec.

Unlike Stuxnet, Duqu does not self-propagate, and is not designed to sabotage industrial systems. In fact, the virus has a 36 day self-destruct mechanism built into it, probably to help prevent its discovery. The most recent version of Duqu was compiled on Monday of this week.

F-Secure's Mikko Hypponen tweeted that "Duqu’s kernel driver (JMINET7.SYS) is so similar to Stuxnet’s driver (MRXCLS.SYS) that our back-end systems actually thought [it was] Stuxnet."

Symantec concludes that the data which Duqu is shipping out of the infected systems "may be used to enable a future Stuxnet-like attack".

The Stuxnet worm was designed to sabotage supervisory control and data acquisition (SCADA) systems made by German technology giant Siemens, and was targetted at nuclear power plants in Iran.

This prompted fears that hackers could take control of nuclear facilities, although the dominant theory is that US and Israeli intelligence forces had a hand in its creation. In February, the Daily Telegraph reported that a video played at the retirement party of an Israeli Lieutenant General depicted Stuxnet among images of his professional achievements.


Comments 

There are currently no comments on this article

People who read this also read...

 

White Papers

Read article

'Think Lean' When Developing Management System Documentation

Learn how to efficiently and effectively implement a document management system for your organization.

Read article

11 Hiring Trends for 2011

In this document, you'll get the insider info you need to give potential employers what they want and beat your competition in 2011. You'll learn about the most valuable certifications and the game-changing skills that can lead to more job security and stability.

Read article

12 Hiring Manager Secrets to Getting the IT Job You Want

Learn how you can make yourself a more attractive candidate now with PrepLogic's free 12 Hiring Manager Secrets to Getting the Job You Want.

More
Advertisement
div class="banner">