Cyberattack forecast after spy virus found
By Emily Chung, CBC News
Posted: Oct 19, 2011 11:45 AM ET
Last Updated: Oct 19, 2011 4:55 PM ET
Related
External Links
(Note:CBC does not endorse and is not responsible for the content of external links.)
I think that Stuxnet is coming from the U.S. government, most likely in cooperation with the Israelis, said computer virus researcher Mikko Hypponen. Like other security experts, he thinks the new virus, Duqu, was written by the same authors as Stuxnet. Emily Chung/CBCThe discovery of an espionage computer virus in Europe similar to the virus that attacked Iran's nuclear plants last year suggests that a new, similar cyberattack is about to launch, a computer virus researcher says.
The new virus, Duqu, was first reported by security company Symantec on its blog Tuesday. Its code is very similar to that of Stuxnet, the virus detected last year that was designed to sabotage equipment at Iranian nuclear plants. However, Duqu is designed for spying and information gathering rather than for sabotaging industrial control systems.
Mikko Hypponen, chief research officer for F-Secure, a Helsinki-based IT security company, said Wednesday that Stuxnet likely also went through a spying phase, likely in late 2008 or early 2009, that helped its creators plan their subsequent attack, which began in the summer of 2009.
"If that theory is correct, this information gathering phase [by Duqu] will next lead to a future attack," Hypponen told the SecTor computer security conference in Toronto during a keynote talk.
He said it's not clear who the target is.
Hyponnen agrees with other IT security experts that Duqu was almost certainly written by Stuxnet's authors, since a lot of their source code is identical.
"No one else has the Stuxnet source code," he said.
"I think that Stuxnet is coming from the U.S. government, most likely in cooperation with the Israelis," added Hypponen, who has been conducting research on computer viruses for 20 years. "Can't prove that, but that's pretty clear when you look at the amount of know-how that went into building Stuxnet, the amount of money it must have taken, the amount of skilled persons behind it."
Symantec said it it first obtained samples of Duqu from European computer systems on Oct. 14 via a research lab with "strong international connections."
Duqu's purpose appears to be to "gather intelligence and assets from entities, such as industrial control system manufacturers, in order to more easily conduct a future attack against another third party," Symantec reported. Associated PressSymantec said Duqu, a type of malicious code known as a remote access Trojan, has parts that are "nearly identical" to the Stuxnet. It targeted companies such as industrial control system manufacturers to gather information that could be useful for a future cyberattack. For example, Duqu was used to install another program that could record keystrokes.
According to a blog post from McAfee Labs, another security company that has received the code for Duqu, the virus communicates with a command server in India.
Symantec estimates attacks using Duqu may have been first conducted as early as December 2010. Duqu does not self-replicate to spread and it deletes itself from the system after 36 days. It sends its data in the form of files that look like JPG image files, including some data that is encrypted. It was named for the fact that it creates files with the prefix "~DQ."
U.S. issues public alert
Following the reports from Symantec and McAfee, the U.S. Department of Homeland Security issued a public alert through its Industrial Control Systems Cyber Emergency Response Team.
"The full extent of the threat posed by W32.Duqu is currently being evaluated," the alert said. "At this time, no specific mitigations are available; however, organizations should consider taking defensive measures against this threat."
It recommended taking measures such as minimizing network exposure for control system devices, putting control system networks behind firewalls, and using secure methods such as Virtual Private Networks for remotely accessing control devices.
The alert added that while security experts don't yet know how Duqu spreads, "the targeted nature of the thread would make social engineering a likely method of attack."
Social engineering refers to a method used to trick a user into installing malware by delivering it through what looks like a person or website that they trust.
Share Tools
Top News Headlines
- NDP wants RCMP inquiry into $90K payment to Duffy
- The NDP has asked the RCMP to launch an investigation into the $90,000 payment from the prime minister's former top aide, Nigel Wright, to Senator Mike Duffy in relation to the Senate expense scandal. more »
- Will alleged Rob Ford video overshadow Toronto casino debate?
- A debate about a proposed downtown casino is supposed to take centre stage at Toronto City Hall on Tuesday, but it seems a safe bet that a still-unseen video of Mayor Rob Ford will continue to be a topic of conversation. more »
- Canadian on EI shut out amid foreign worker influx
- A jobless Canadian IT professional who is collecting employment insurance is upset because he now suspects several recent jobs he applied for went to temporary foreign workers. more »
- Baseball fuels dreams, desperation in Dominican Republic
- The Toronto Blue Jays have a number of stars from the Dominican Republic, but in the shadow of these successful players is an equally important story about hope and poverty, and a country desperately struggling to balance the two. more »
Must Watch
Latest Technology & Science News Headlines
- Xbox launch Tuesday highly anticipated
- Microsoft's next-generation Xbox expected to be revealed Tuesday, and anticipation for the entertainment console's latest evolution is running high. more »
- Netflix and the rise of binge TV watching
- Netflix has been giving viewers the opportunity to watch entire new seasons of TV shows in one sitting and — for better or for worse — many have been doing just that. more »
- Astronaut Chris Hadfield adjusts to 'earthling' life
- Canada's space ambassador, Chris Hadfield, is still readapting to life on this planet after spending 146 days in zero gravity as commander of the International Space Station. For now, though, he's taking his homecoming one step at a time. more »
- Bell Mobility to appeal ruling in 911 lawsuit
- Bell Mobility says the company plans to appeal a Northwest Territories Supreme Court ruling that says the company is liable for charging 911 fees to customers that aren't receiving the service. more »
Bob McDonald's Blog
Chris Hadfield: The gravity of gravity May. 17, 2013 9:58 AM After five months of being Superman and a media superstar, Canadian astronaut Chris Hadfield is now beginning the challenging task of adapting his mortal body and brain to life back on Earth.
Quirks & Quarks
- May 18: Apps for Apes May. 17, 2013 4:26 PM Scientists at more than 2 dozen zoos around the world, including the Toronto Zoo, have been using computer tablets to stimulate our bright orange primate cousins, the orangutans. And the orangutans have been loving it.
Latest Features
- 51 dead after tornado levels Oklahoma suburbs
- Edmonton driver, 62, charged in boy's patio death
- Unknown remains found on Dellen Millard's farm
- Huge tornado hits Oklahoma City suburb, kills 51
- Will alleged Rob Ford video overshadow Toronto casino debate?
- Netflix and the rise of binge TV watching
- B.C. man feared kidnapped in Mexico
- Ray Manzarek of The Doors dies at 74
- Canadian on EI shut out amid foreign worker influx

