All the latest UK technology news, reviews and analysis

Kaspersky Lab argues same team built Stuxnet and Duqu

by Phil Muncaster

03 Jan 2012

Be the first to comment

  • Tweet this

Kaspersky Lab researchers have concluded that the Duqu malware discovered in the latter half of 2011 was indeed created by the same team that built the infamous Stuxnet worm largely thought to have been aimed specifically at disrupting Iran's nuclear program.

In a recent blog post, the firm's chief security expert Alexander Gostev argued that the same platform, dubbed "Tilded" was used by the team to create the two Trojans and other malware besides.

Key to the researchers' conclusions was an in-depth analysis of the drivers used for infecting systems with Stuxnet and Duqu.

In all, they found seven types of drivers with similar characteristics, but argued that for three of these there is no information on what malicious programs they were designed to be used with.

"The methods of dissemination of Stuxnet would have brought about a large number of infections with these drivers; and they can't be attributed either to the more targeted Duqu Trojan due to the compilation date," said Gostev.

"We consider that these drivers were used either in an earlier version of Duqu, or for infection with completely different malicious programs, which moreover have the same platform and, it is likely, a single creator-team."

The creators of Stuxnet and Duqu create a new version of the driver several times a year, changing parameters such as the registry key, according to Kaspersky Lab.

The conclusions reached by Kaspersky Lab fly are at odds with some others in the security space, notably BitDefender, which argued that the aims of the two Trojans were too conflicting for them to have been built by the same team.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

30%

2%

14%

54%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Functional Oracle Support Analyst

Functional Oracle Support Analyst - EBS Financials, Support...

Oracle E-Business Suite Technical Consultant

Oracle E-Business Suite Technical Consultant - EBS...

Oracle Applications DBA

Oracle Applications DBA - East London - All salaries...

Oracle Functional Consultants

Oracle Functional Consultants - Financial - Project Accounting...

To send to more than one email address, simply separate each address with a comma.