Duqu Attackers Wiped All Linux CandC Servers to Cover Tracks

Published: Nov 30, 2011
Updated: Feb 2, 2021
3 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Shortly after Symantec publicized the Duqu Trojan in October, the unknown perpetrators behind the data-gathering malware removed traces of their activity from all their command and control servers to cover their tracks, Kaspersky Lab researchers have discovered.

Despite the “massive cleanup,” Kaspersky researchers were still able to gather information on Duqu’s C&C infrastructure, Vitaly Kamluk, chief malware analyst at Kaspersky Lab, wrote on the company’s SecureList blog. Along with the command and control servers in India and Belgium, which have since been shut down by law enforcement authorities, Duqu communicated with other servers in Vietnam and the Netherlands, said Kamluk.

Other servers were used as main C&C proxies, and some were used by attackers to bounce from one location to another to make it difficult for authorities to track the malicious traffic. Kaspersky Lab estimated “more than a dozen” C&C active servers for the Duqu Trojan dating as far back as 2009, Kamluk wrote.

A day later, on Oct. 20, the attackers “wiped” every single server they had used over the past three years in India, Vietnam, Germany, the United Kingdom, Singapore, Switzerland, the Netherlands and South Korea, to name a few. Unfortunately, the “most interesting server” in India was cleaned “hours before” the hosting company agreed to make an image for researchers to analyze, Kamluk said.

“We still do not know who is behind Duqu and Stuxnet,” Kamluk said, adding that “attackers have covered their tracks quite effectively.” The “mothership” server also remains a mystery, he said.

Many of the servers that had been hacked to become part of Duqu’s infrastructure were running Linux, namely CentOS 5.2, 5.4 or 5.5, a community version very similar to Red Hat Enterprise Linux. Both 32-bit and 64-bit machines had been compromised, according to Kamluk. It is not clear whether it was “just a coincidence” or if the attackers preferred CentOS 5.x.

Kaspersky researchers spent quite some time trying to figure out how the servers were compromised. The servers were running OpenSSH 4.3, which comes by default on CentOS, and as soon as the attackers got in, they updated the software to version 5.8.

While this suggests that the attackers were closing a hole once in the server to prevent anyone else from coming in, and there have been reports of a possible zero-day vulnerability in the client software used to access servers, Kaspersky researchers could not say so definitely. This wouldn’t be the first zero-day exploit being used by Duqu, as researchers have already uncovered one targeting the Microsoft Windows kernel.

Advertisement

“There must be a good reason why the attackers are so concerned about updating OpenSSH 4.3 to version 5. Unfortunately, we do not know the answer to this question,” Kamluk wrote, and asked Linux administrators and OpenSSH experts for suggestions.

Even though there was a possibility of a zero-day, the researchers thought it was more likely that the servers’ root passwords were brute-forced, based on a log of a user attempting to log in as root multiple times over an 8-minute period from an IP address in Singapore before finally succeeding.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。