Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

3/21/2012
04:22 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Duqu Alive And Well: New Variant Found In Iran

Researchers at Symantec dissect part of new, retooled version of the reconnaissance-gathering malware

The creators of Duqu may not have used traditional malware writers to craft their code, but they have done something that malware writers do: They released a new variant of their code with just enough tweaks to evade detection.

A day after researchers from Kaspersky Lab revealed that with the help of the security community, they had cracked the mystery of the programming language used in Duqu, researchers from Symantec yesterday announced they had discovered a new variant of Duqu -- the first one spotted since October. The first two were found in the wild in November 2010.

Vikram Thakur, principal manager at Symantec Security Response, says the creators of Duqu -- which Symantec and Kaspersky agree are the same ones who are behind Stuxnet -- basically changed a few bytes here and there to allow the malware to sneak past detection tools, including an open-source one built by the Laboratory of Cryptography and System Security (CrySyS Labs). "This is round two of the same thing: the old code, tweaked a bit," Thakur says.

The attackers changed the encryption algorithm and, rather than employing a stolen digital certificate as they had done before, used a phony Microsoft cert to make the driver appear to be legitimate. The sample discovered by Symantec came out of Iran, Thakur says, and it's just one piece of the malware package: specifically, the "loader," which installs the rest of the malware when the victim's machine restarts. The compile date on the malware is Feb. 23, 2012.

"We just found one component. We don't have the main file that landed on the computer or the config file where the command-and-control server is," he says.

Even so, it was enough evidence to show that the Duqu gang has not given up, despite all of the publicity and research focused on it. "These guys have a mission, whatever that might be, and don't care about what the security community or media might know about the threat," Thakur says. "They are extremely confident that it won't get back to them or be attributable to the person behind it. So they are continuing business as it is."

Roel Schouwenberg, senior antivirus researcher for Kaspersky Lab, says the latest move by the Duqu creators is that they are watching and will change their code as necessary. "It shows that their operations are still ongoing," Schouwenberg says. "It also means that up until that time, they didn't see a need to actually release new variants to evade detection."

And they obviously plan to use their existing framework despite the research community's scrutiny. They continue to leverage their investment in that code, security experts say.

Meanwhile, both Symantec and Kaspersky maintain that Duqu is more of an intelligence-gathering, cyberespionage malware, while Stuxnet was built to sabotage its target. Symantec's Thakur says the tricky part is that it's difficult to gain visibility into Duqu because it's so targeted. "We think Duqu does reconnaissance and [the attackers] take action based on the data they get back. Whether it's one mission ... is still up for debate," he says. "It's definitely by the same people."

Kaspersky's Schouwenberg says it's no surprise that Duqu showed up again in Iran. "Stuxnet's mission was sabotage. Duqu's mission was espionage and intelligence-gathering. Everything we have seen so far indicates that this operation is basically to gauge the status of the [Iranian] nuclear progress," he says.

And this won't be the last variant of Duqu. "I have no doubt we are going to see additional versions of Duqu. Maybe they are already out there," Thakur says. It's less likely there will be a new Stuxnet variant attacking the same Iranian nuclear facility, however, he says.

While enterprises, in general, don't have to worry much about Duqu, the sophisticated malware has added a new dimension to cyberespionage. "Duqu's espionage is clearly much better written than the average 'APT' espionage thing we see on a daily basis," Kaspersky's Schouwenberg says. "People should be paying attention to Duqu. There's a lot of interest in IP [intellectual property] out there."

More technical details on the new Duqu variant are available here in a Symantec blog post.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
WJOHN000
50%
50%
WJOHN000,
User Rank: Apprentice
3/22/2012 | 7:07:31 AM
re: Duqu Alive And Well: New Variant Found In Iran
Duqu's mission was espionage and intelligence-gathering.
Bprince
50%
50%
Bprince,
User Rank: Ninja
3/21/2012 | 10:51:25 PM
re: Duqu Alive And Well: New Variant Found In Iran
The plot thickens. It's not unlikely we will see a new version of Stuxnet soon as well...
Brian Prince, InformationWeek/Dark Reading Comment Moderator
44% of Security Threats Start in the Cloud
Kelly Sheridan, Staff Editor, Dark Reading,  2/19/2020
Zero-Factor Authentication: Owning Our Data
Nick Selby, Chief Security Officer at Paxos Trust Company,  2/19/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
How Enterprises Are Developing and Maintaining Secure Applications
How Enterprises Are Developing and Maintaining Secure Applications
The concept of application security is well known, but application security testing and remediation processes remain unbalanced. Most organizations are confident in their approach to AppSec, although others seem to have no approach at all. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-9405
PUBLISHED: 2020-02-26
IBL Online Weather before 4.3.5a allows unauthenticated reflected XSS via the redirect page.
CVE-2020-9406
PUBLISHED: 2020-02-26
IBL Online Weather before 4.3.5a allows unauthenticated eval injection via the queryBCP method of the Auxiliary Service.
CVE-2020-9407
PUBLISHED: 2020-02-26
IBL Online Weather before 4.3.5a allows attackers to obtain sensitive information by reading the IWEBSERVICE_JSONRPC_COOKIE cookie.
CVE-2020-9398
PUBLISHED: 2020-02-25
ISPConfig before 3.1.15p3, when the undocumented reverse_proxy_panel_allowed=sites option is manually enabled, allows SQL Injection.
CVE-2015-5201
PUBLISHED: 2020-02-25
VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as packaged in Red Hat Enterprise Virtualization before 3.5.6 when VSDM is run with -spice disable-ticketing and a VM is suspended and then restored, allows r...