HomeSecurityThe first victims of the infamous Stuxnet worm have been revealed

First victims of the infamous Stuxnet worm revealed

STUXNET_620_610x344

More than four years have passed since the discovery of the worm Stuxnet, one of the most sophisticated and dangerous malware programs, considered to be the first digital weapon. However, there are still many mysteries surrounding this story. One important question is what exactly were the goals of Stuxnet's overall operation. Now, after analyzing more than 2,000 Stuxnet files, collected over a two-year period, Kaspersky Lab can identify the worm's first victims.

Initially, researchers had no doubt that the attack as a whole was targeted. The Stuxnet worm code looked professional and proprietary. There was evidence that extremely precise zero-day. However, it was not yet known what kind of organizations had been initially attacked and how the malware finally managed to achieve its goal of penetrating uranium enrichment centrifuges at specific, secret facilities.

The new analysis sheds light on the above questions. The operations of all five organizations initially attacked are located in the same area as ICS's headquarters in Iran and either develop materials for ICS or procure materials and components from it. The fifth organization attacked is of the greatest interest because it produces – in addition to industrial automation products – centrifuges for uranium enrichment. This type of equipment is believed to be the main target of Stuxnet.

 Kaspersky Lab Stuxnet worm

Apparently, the attackers expected these organizations to exchange data with their customers, such as uranium enrichment plants, which would allow them to inject malware into the target facilities. The result shows that their plan was indeed successful.

“Analyzing the business activities of the first organizations that fell victim to Stuxnet allows us to better understand how the campaign was designed as a whole. This is an example of an attack vector against a supply chain, where malware is transmitted to target organizations indirectly, through the networks of the organization’s partners,” said Alexander Gostev, Chief Security Expert at Kaspersky Lab.

Kaspersky Lab experts have made another interesting discovery, however. Stuxnet was not only spread via “infected” USB sticks plugged into PCs. This was the initial theory and explained how the malware could sneak into a location without a direct Internet connection. However, data collected during the analysis of the first attack showed that the first worm sample (Stuxnet.a) had been created just a few hours before it appeared on a PC in the first organization attacked. Given this tight timeline, it is hard to imagine that an attacker could have assembled the sample, put it on a USB stick, and transported it to the targeted organization within a few hours. It is reasonable to assume that in this case, those behind Stuxnet used different techniques, in addition to infection via USB.

The latest technical information about some of the factors behind the Stuxnet is available on Securelist, as well as in the new book, “Countdown to Zero Day,” by journalist Kim Zetter. The book includes previously unknown information about Stuxnet. Some of this information is based on interviews with members of Kaspersky Lab’s Global Research and Analysis Team.

Source: secnews.gr

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS