You have commented 339 times on Rantburg.

Your Name
Your e-mail (optional)
Website (optional)
My Original Nic        Pic-a-Nic        Sorry. Comments have been closed on this article.
Bold Italic Underline Strike Bullet Blockquote Small Big Link Squish Foto Photo
Science
US firm finds new 'Stuxnet-related' worm
2012-03-27
Researchers at Symantec say they possess part of the worm which causes it to load on a computer after it restarts.

Researchers at the US computer security firm Symantec say they have obtained a new version of an Internet worm that has been linked to the Stuxnet virus.

Stuxnet is the name of a computer virus that was detected in 2010, which reportedly caused significant damage to Iran's uranium enrichment program.

It targeted Siemens supervisory control and data acquisition (SCADA) systems, used by Iran to enrich uranium through spinning centrifuges. Foreign media reports speculated that Israel or the US, or both, were behind the attack.

Five months ago, Symantec detected a computer worm, Duqu, which sends back information on systems that would help attackers prepare a future strike.

Duqu "must either have been created by the same group that authored Stuxnet, or by a group that somehow managed to obtain Stuxnet's source code," Symantec said following the discovery.

Now, Symantec said, part of a new version of Duqu has been found.

Researchers at the firm said they came to possess a part of the worm which causes it to load on a computer after it restarts.

"The compile date on the Duqu component is February 23, 2012, so this new version has not been in the wild for very long," a post on Symantec's blog said. "We can see the authors have changed just enough of the threat to evade some security product detection."

Last year, Symantec concluded that the mysterious authors behind Stuxnet, described as the most sophisticated cyber weapon on the planet, appear to be planning another strike, and have updated their advanced spy program designed to search out weaknesses.

The Duqu worm was believed to have infected systems in countries from Vietnam to La Belle France, including Iran.

In recent days, another cyber security company, Kaspersky Lab, reported that Duqu had been written in "pure C," an old programming language "long since discarded by most programmers in favor of newer versions," ABC News reported.

Quoting Kaspersky researchers, ABC said that the old language was used "to make sure that the worm could infect just about everything it touched."
Posted by:trailing wife

#2  Linux is still written in "C". Lots of stuff is. c++ can even be exported as "c" with the proper compiler option. What is this ancient language argument. Fortran, PL1, Cobol, Pascal, BAL, Snobol etch qualify as old. Ancient? Maybe something Ada could have used programming her dad mythical steam difference engines?
Posted by: Water Modem   2012-03-27 09:04  

#1  Since IP sockets library and byte injection is probably the core of DUQU 'C' is the obvious choice.
Posted by: Bright Pebbles   2012-03-27 08:53  

00:00