
And it wasn't long after the appearance of the last virus we studied, we hadn't quite recovered from Stuxnet... when this happened:
According to an announcement by security software company Symantec, the infamous worm codenamed Stuxnet is back and this time it may be more threatening than before. The new malware is currently known as Duqu. According to an announcement by security software company Symantec, the infamous worm codenamed Stuxnet is back and this time it may be more threatening than before. The new malware is currently known as Duqu.
Duqu has already been detected on computers of large companies. A first difference compared to its predecessor is that it does not only target nuclear facilities - as Stuxnet did with the Iranian nuclear program - but has a large "repertoire". Symantec believes that Duqu collects information in order to use it for future attacks.
[alert variation=”alert-info”]The researchers found that the Dυqu code has many similarities to that of Stuxnet, so either it was written by the same person, or someone else somehow obtained the source code and created a variant. It is also interesting that Dυqu self-deletes after 36 days on a computer, making it more difficult to detect.[/alert]

Duqu's presence in Iran reinforces the view that Duqu and Stuxnet are two sides of the same coin. It is recalled that the Stuxnet worm infected Iran's nuclear facilities in the city of Dusher in 2010, causing work to stop at the Persian plant.
According to Kaspersky analysts, the core module of Dυqu consists of three parts:
1) the kernel driver that drops a rogue library into system processes,
2) the DLL itself that handles, among other things, communication with the command-and-control (C&C) server, and
3) the configuration file.
In addition, there is a secondary module, which takes the form of a keylogger with the ability to intercept information.
Dυqu's architecture is highly flexible, allowing it to self-upgrade, change C&C servers, and install additional components at any time.
No one can say what its origin is, but if it is directly related to Stuxnet, US and Israeli intelligence agencies are at the top of the list of suspects.
Of particular interest is the statement by Kaspersky Lab published in November 2011:
Kaspersky Lab announces that all of its products detect the vulnerability used to distribute the infamous Trojan Duqu and all its variants.
Kaspersky Lab experts have successfully implemented protection methods against Trojan.Win32.Duqu.a and other malicious programs that exploit the vulnerability codenamed CVE-2011-3402. The zero-day vulnerability was discovered in the Win32k TrueType Font parser. This vulnerability could affect various Office programs.
For example, a specially crafted Microsoft Word document could be used to allow cybercriminals to gain greater access privileges to a user's computer and run malicious code.
This concludes our review today. Any comments, additional information, or even your personal experiences with the viruses we mention are always welcome. We are renewing our appointment for next Saturday to discover together the next devastating virus.
Stay tuned to SecNews to learn even more!



