Subscribe free to our newsletters via your
. 24/7 Space News .




CYBER WARS
More 'Stuxnet' cyberattacks feared
by Staff Writers
Mountain View, Calif. (UPI) Oct 20, 2011


disclaimer: image is for illustration purposes only

The makers of a computer virus aimed at disabling Iran's nuclear facilities appear to be back in Europe with a precursor to a new attack, U.S. experts say.

The attacks by the malware named Stuxnet in 2009 and 2010 were responsible for disabling the controls of industrial equipment used at the Iranian nuclear research site at Natanz -- causing problems for its centrifuges, President Mahmoud Ahmadinejad confirmed last year.

Now, industrial computers in Europe are being infected with a "Trojan horse" software bug similar to Stuxnet that is likely the precursor to a new attack, the U.S. computer security company Symantec said.

Liam O Murchu, a Symantec security supervisor, wrote on his official blog that European researchers had provided him with examples of a malware dubbed "Duqu," which contains sections that are nearly identical to Stuxnet and appears to have been written by the same authors.

"The real surprising thing for us is that these guys are still operating," he told Wired magazine. "We thought these guys would be gone after all the publicity around Stuxnet. That's clearly not the case.

"They've clearly been operating over the last year. It's quite likely that the information they are gathering is going to be used for a new attack. We were just utterly shocked when we found this," he added.

The Stuxnet worm represented a new threat level -- experts said it was the first discovered to be built to for spying on and subverting industrial systems. It was also the first to contain a programmable logic controller in its malicious code payload.

It attacked industrial control equipment made by the German manufacturer Siemens between June 2009 and May 2010, taking aim at specific organizations in Iran on three occasions. It infected Natanz and four other Iranian industrial facilities, The New York Times reported.

The newspaper in January said Israel had set up an array of centrifuges in an elaborate mock-up of a suspected Iranian uranium enrichment site -- something that would have been needed to provide the sophistication for programming the Stuxnet malware.

The purpose of the new Duqu malware, O Murchu said in his blog post, is to "gather intelligence data and assets from entities, such as industrial control system manufacturers, in order to more easily conduct a future attack against another third party."

The attackers, he said, "are looking for information such as design documents that could help them mount a future attack on an industrial control facility."

Duqu isn't a self-replicating worm like Stuxnet, but a "Trojan horse" information-stealer that could record keystrokes and gain other secret system information.

"The attackers were searching for assets that could be used in a future attack," O Murchu said.

The security expert declined to say which European countries were attacked with the Duqu malware but did tell Wired they hadn't been grouped in any specific geographical target. He warned that could change quickly if more variants of the virus are found.

Guilherme Venere and Peter Szor of the U.S. computer security firm McAfee Labs wrote this week that there's no doubt the Duqu malware has the same authors as Stuxnet.

"The Stuxnet worm utilized two 'stolen' digital certificates belonging to two companies from Taiwan, which operated in the same business district," they wrote on their blog, while the new malware "was signed with yet another key belonging to the company Cmedia, in Taipei.

"It is highly likely that this key, just like the previous two, known cases, was not really stolen from the actual companies but instead directly generated in the name of such companies at a (commercial certificate authority) as part of a direct attack," they said.

.


Related Links
Cyberwar - Internet Security News - Systems and Policy Issues






Comment on this article via your Facebook, Yahoo, AOL, Hotmail login.

Share this article via these popular social media networks
del.icio.usdel.icio.us DiggDigg RedditReddit GoogleGoogle








CYBER WARS
Stuxnet-like virus points to new round of cyber war
San Francisco (AFP) Oct 20, 2011
Internet security specialists have warned of a new round of cyber warfare in the form of a computer virus similar to the malicious Stuxnet worm believed to have targeted Iran's nuclear program. Analysts at US firms McAfee and Symantec agreed that a sophisticated virus dubbed "Duqu" has been unleashed on an apparent mission to gather intelligence for future attacks on industrial control syste ... read more


CYBER WARS
Lunar Probe to search for water on Moon

Subtly Shaded Map of Moon Reveals Titanium Treasure Troves

NASA's Moon Twins Going Their Own Way

Titanium treasure found on Moon

CYBER WARS
Mars Landing-Site Specialist

New Mystery on Mars's Forgotten Plains

Russian scientists want to join Europe's ExoMars mission

UK Space Agency announces seed funding for Mars exploration

CYBER WARS
Space tourism gaining momentum

NASA Veteran Alan Stern to Lead Florida Space Institute

Astrotech Subsidiary Awarded Task Order for NASA Mission

ASU in space: 7 current missions, more in the wings

CYBER WARS
China's first space lab module in good condition

Takeoff For Tiangong

Snafu as China space launch set to US patriotic song

Civilians given chance to reach for the stars

CYBER WARS
Expedition 30 to ISS could be launched on Dec 21

ISS could be used for satellite assembly until 2028

Ultrasound 2: Taking Space Imaging to the Next Level

CU-Boulder to play key role in global student space experiment competition

CYBER WARS
ILS Proton Launches ViaSat-1 for ViaSat

Final checks for first Soyuz launch from Kourou

Soyuz is put through its paces for Thursday's launch

Russia blames scientists for rocket crashes

CYBER WARS
NASA's Spitzer Detects Comet Storm In Nearby Solar System

Photo Reveals Planet-Size Object as Cool as Earth

Spiral Arms Point to Possible Planets in a Star's Dusty Disk

UChicago launches search for distant worlds

CYBER WARS
Greenpeace criticises Japan radiation screening

Apple profit soars but misses high expectations

China rare earths giant halts output as prices fall

Camera lets people shoot first, focus later




The content herein, unless otherwise known to be public domain, are Copyright 1995-2014 - Space Media Network. AFP, UPI and IANS news wire stories are copyright Agence France-Presse, United Press International and Indo-Asia News Service. ESA Portal Reports are copyright European Space Agency. All NASA sourced material is public domain. Additional copyrights may apply in whole or part to other bona fide parties. Advertising does not imply endorsement,agreement or approval of any opinions, statements or information provided by Space Media Network on any Web page published or hosted by Space Media Network. Privacy Statement