Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity
    • Networking

    Indian Authorities Seize Suspected Duqu CandC Server

    Written by

    Fahmida Y. Rashid
    Published October 31, 2011
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Government officials in India seized equipment from a Web hosting company in Mumbai after Symantec said the server was communicating with Duqu-infected machines, Reuters reported.

      Officials from India’s Department of Information Technology seized hard drives and other components from the server suspected of being part of the Duqu Trojan’s command and control infrastructure, two workers at Mumbai’s Web Werks told Reuters Oct. 28. Symantec first publicized the malware earlier this month and security experts have identified infected systems in parts of Europe, United States, Iran and Sudan.

      Originally considered a follow-up to the dangerous Stuxnet worm which infected industrial control systems and set back Iran’s nuclear program by damaging uranium concentration centrifuges, researchers remain unclear about the Duqu Trojan’s intended purpose.

      Only a handful of infections have been found thus far, making it difficult to identify the target or purpose. The equipment seized from Web Werks may hold valuable data to help investigators determine who built Duqu and why, according to Reuters.

      “This one is challenging,” Marty Edwards, director of the United States Department of Homeland Security’s Industrial Control Systems Cyber Emergency Response Team, told Reuters. “It’s a very complex piece of software,” he said, adding that the agency was working with counterparts in other countries to uncover more information.

      The anonymous Web Werks employees were unable to identify the customer who was using the server or explain how Duqu got into the data center.

      Symantec researchers raised the alarm regarding Duqu earlier this month because of the code similarities with Stuxnet. Duqu appears to be primarily designed for reconnaissance and doesn’t seem to have the destructive capabilities that Stuxnet has. Symantec speculated it was looking for intellectual property to steal from companies that could be used on future attacks against critical infrastructure such as power plants, oil refineries and pipelines. The code similarities were an indicator that the same team behind Stuxnet had a hand in Duqu’s development, according to Symantec.

      Dell SecureWorks’ Counter Threat Unit found many of the common elements between Stuxnet and Duqu that had been “observed in other unrelated threats,” the research team wrote in their analysis. The kernel drivers that load encrypted DLL (Dynamic Load Library) files and built-in encryption and stealth capabilities, such as rootkits, were in both Duqu and Stuxnet, but weren’t unique to the two pieces of malware, Dell SecureWorks said.

      While Stuxnet and Duqu had variants where the kernel driver file was digitally signed using a software signing certificate from Taiwanese company JMicron, that was not proof that there was a link between the two because “compromised signing certificates can be obtained from a number of sources,” the team said.

      All of the similarities between Duqu and Stuxnet are in the kernel driver’s “injection” capabilities and while it’s possible the code share a common source, the evidence linking the two is “circumstantial at best and insufficient to form a direct relationship,” according to Dell SecureWorks.

      BitDefender’s Bogdan Botezatu had noted that the Stuxnet code had been reverse engineered and was publicly available for other developers to use as a foundation for other malware.

      Since Duqu doesn’t appear to target any specific sector or vendor, Dell SecureWorks also downplayed the risk of Duqu as an advanced persistent threat (APT). “While Duqu does provide capabilities used by other tools observed in APT-related intrusions, an assessment of the particular threat requires knowledge of the adversary, targeted organization and assets and the scope of attacks,” the team wrote.

      Fahmida Y. Rashid
      Fahmida Y. Rashid

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.