NEWS / GENERAL

Researchers prove that Stuxnet weapon has at least 4 cousins

29 Dec, 2011, 11:39 am IST | by | General

The Stuxnet virus that last year damaged Iran's nuclear program was likely one of at least five cyber weapons developed on a single platform whose roots trace back to 2007, according to new research from Russian computer security firm Kaspersky Lab.

Duqu linked to server in Mumbai

More than what meets the eye? 

 

 

Security experts widely believe that the United States and Israel were behind Stuxnet, though the two nations have officially declined to comment on the matter. A Pentagon spokesman on Wednesday declined comment on Kaspersky's research, which did not address who was behind Stuxnet. Stuxnet has already been linked to another virus, the Duqu data-stealing trojan, but Kaspersky's research suggests the cyber weapons program that targeted Iran may be far more sophisticated than previously known. Kaspersky's director of global research & analysis, Costin Raiu, told Reuters on Wednesday that his team has gathered evidence that shows the same platform that was used to build Stuxnet and Duqu was also used to create at least three other pieces of malware.

 

Raiu said the platform is comprised of a group of compatible software modules designed to fit together, each with different functions. Its developers can build new cyber weapons by simply adding and removing modules. "It's like a Lego set. You can assemble the components into anything: a robot or a house or a tank," he said. Kaspersky named the platform "Tilded" because many of the files in Duqu and Stuxnet have names beginning with the tilde symbol "~" and the letter "d."

 

Researchers with Kaspersky have not found any new types of malware built on the Tilded platform, Raiu said, but they are fairly certain that they exist because shared components of Stuxnet and Duqu appear to be searching for their kin. When a machine becomes infected with Duqu or Stuxnet, the shared components on the platform search for two unique registry keys on the PC linked to Duqu and Stuxnet that are then used to load the main piece of malware onto the computer, he said.

 

Kaspersky recently discovered new shared components that search for at least three other unique registry keys, which suggests that the developers of Stuxnet and Duqu also built at least three other pieces of malware using the same platform, he added. Those modules handle tasks including delivering the malware to a PC, installing it, communicating with its operators, stealing data and replicating itself. Makers of anti-virus software including Kaspersky, U.S. firm Symantec Corp and Japan's Trend Micro Inc <4704.T> have already incorporated technology into their products to protect computers from getting infected with Stuxnet and Duqu.

 

Yet it would be relatively easy for the developers of those highly sophisticated viruses to create other weapons that can evade detection by those anti-virus programs by the modules in the Tilded platform, he said. Kaspersky believes that Tilded traces back to at least 2007 because specific code installed by Duqu was compiled from a device running a Windows operating system on August 31, 2007.

 

Reuters

Tags: Stuxnet virus , virus , researchers , Duqu virus , Duqu , anti virus , Kaspersky , Symantec Corp. , Trend Micro

RELATED STORIES

Experts say Iran has 'neutralized' Stuxnet virus

Experts say Iran has 'neutralized' Stuxnet virus

Iranian engineers have succeeded in neutralizing and purging the computer virus known as Stuxnet from their country's nuclear machinery, European ...

Android more vulnerable to malware than iOS

Norton launches 2012 editions of their Antivirus and Internet Security suites

New Android Trojan Records Calls, Uploads Them to Remote Server

Google Warns Windows Users of Malware

4.5 Million PCs Slayed by 'Indestructible' Botnet

Virus Protection Takes Inspiration from Ants

Stuxnet - Cyber Warfare

03 Jul, 2011, 05:22 pm IST

Stuxnet - Cyber Warfare

 

OPINIONS

Padmini Harchandrai

The latest "should they-shouldn't they" event with Facebook is the lift of the minimu...

MORE OPINIONS

Leaked Images, Availability, Pricing,
Specs, Pre-order

features

Top 5 potential Gmail alternatives

Top 5 potential Gmail alternatives

Google’s Gmail service is arguably the most advanced and feature-packed...

By Naina Khedekar

The Future of Broadband - views from industry leaders

The Future of Broadband - views from industry leaders

One of the other events that took place at the same venue as the recent...

By Rossi Fernandes

Tech2 goes around the World IT Show 2012, Seoul

Tech2 goes around the World IT Show 2012, Seoul

Tech2 was part of an entourage that was invited for the Korea IT Show and...

By Rossi Fernandes

MORE FEATURES