Duqu Alive And Well: New Variant Found In Iran

  /     /     /  
Publicated : 22/11/2024   Category : security


Duqu Alive And Well: New Variant Found In Iran


Researchers at Symantec dissect part of new, retooled version of the reconnaissance-gathering malware



The creators of Duqu may not have used traditional malware writers to craft their code, but they have done something that malware writers do: They released a new variant of their code with just enough tweaks to evade detection.
A day after
researchers from Kaspersky Lab revealed that with the help of the security community, they had cracked the mystery of the programming language used in Duqu
, researchers from Symantec yesterday announced they had discovered a new variant of Duqu -- the first one spotted since October. The first two were found in the wild in November 2010.
Vikram Thakur, principal manager at Symantec Security Response, says the creators of Duqu -- which Symantec and Kaspersky agree are the same ones who are behind Stuxnet -- basically changed a few bytes here and there to allow the malware to sneak past detection tools, including an open-source one built by the Laboratory of Cryptography and System Security (CrySyS Labs). This is round two of the same thing: the old code, tweaked a bit, Thakur says.
The attackers changed the encryption algorithm and, rather than employing a stolen digital certificate as they had done before, used a phony Microsoft cert to make the driver appear to be legitimate. The sample discovered by Symantec came out of Iran, Thakur says, and its just one piece of the malware package: specifically, the loader, which installs the rest of the malware when the victims machine restarts. The compile date on the malware is Feb. 23, 2012.
We just found one component. We dont have the main file that landed on the computer or the config file where the command-and-control server is, he says.
Even so, it was enough evidence to show that the Duqu gang has not given up, despite all of the publicity and research focused on it. These guys have a mission, whatever that might be, and dont care about what the security community or media might know about the threat, Thakur says. They are extremely confident that it wont get back to them or be attributable to the person behind it. So they are continuing business as it is.
Roel Schouwenberg, senior antivirus researcher for Kaspersky Lab, says the latest move by the Duqu creators is that they are watching and will change their code as necessary. It shows that their operations are still ongoing, Schouwenberg says. It also means that up until that time, they didnt see a need to actually release new variants to evade detection.
And they obviously plan to use their existing framework despite the research communitys scrutiny. They continue to leverage their investment in that code, security experts say.
Meanwhile, both Symantec and Kaspersky maintain that Duqu is more of an intelligence-gathering, cyberespionage malware, while Stuxnet was built to sabotage its target. Symantecs Thakur says the tricky part is that its difficult to gain visibility into Duqu because its so targeted. We think Duqu does reconnaissance and [the attackers] take action based on the data they get back. Whether its one mission ... is still up for debate, he says. Its definitely by the same people.
Kasperskys Schouwenberg says its no surprise that Duqu showed up again in Iran. Stuxnets mission was sabotage. Duqus mission was espionage and intelligence-gathering. Everything we have seen so far indicates that this operation is basically to gauge the status of the [Iranian] nuclear progress, he says.
And this wont be the last variant of Duqu. I have no doubt we are going to see additional versions of Duqu. Maybe they are already out there, Thakur says. Its less likely there will be a new Stuxnet variant attacking the same Iranian nuclear facility, however, he says.
While enterprises, in general, dont have to worry much about Duqu, the sophisticated malware has added a new dimension to cyberespionage. Duqus espionage is clearly much better written than the average APT espionage thing we see on a daily basis, Kasperskys Schouwenberg says. People should be paying attention to Duqu. Theres a lot of interest in IP [intellectual property] out there.
More technical details on
the new Duqu variant are available here in a Symantec blog post
.
Have a comment on this story? Please click Add Your Comment below. If youd like to contact
Dark Readings
editors directly,
send us a message
.

Last News

▸ There are plenty of online tools for reporting bugs. ◂
Discovered: 23/12/2024
Category: security

▸ 27 Million South Koreans Hit by Online Gaming Theft. ◂
Discovered: 23/12/2024
Category: security

▸ Homeland Security Background Checks Breach Raises Concerns. ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Duqu Alive And Well: New Variant Found In Iran