Nasty "Duqu" Worm Exploits Same Microsoft Office Bug as Stuxnet
November 2, 2011 12:32 PM
No, not THAT Dooku, it's the Duqu worm.
(Source: LucasFilm, Ltd.)
Customers are at high risk after a gaping hole was found in MSO's security
If you just received a Word document from a colleague, don't open it until you verify they
sent it. A new worm is sweeping the globe and it hides inside innocent-looking Word documents, waiting to strike via a hitherto unknown vulnerability.
I. Duqu Worm Taps Microsoft Vulnerability, Proliferates
The "Duqu" worm is currently sweeping corporate networks worldwide, seeking to infect as many machines as possible in what appears to be an effort to target power plants, oil refineries and pipelines.
Microsoft Corp. (
) revealed this week that Duqu uses similar code to
the Stuxnet worm
crippled Iranian nuclear power computer systems
in 2010. Many have voiced suspicions that U.S. defense or intelligence agencies were behind Stuxnet, but it appears extreme unlikely that the U.S. government had anything to do with Duqu. In fact, Duqu appears to be targeting U.S. allies.
The worm exploits a hitherto-unknown zero-day flaw in Microsoft Office and the Windows operating system. When the victim receives and opens an infected Word document -- which appears entirely normal -- the worm installs itself on their machines and takes control of the system.
The worm then proceeds to propogate, by opening your contacts lists in programs like Thunderbird and Outlook and then emailing all of your contacts infected documents.
The Duqu worm exploits a previously unknown vulnerability to execute malicious shellcode and gain system access in a sophisticated cyberespionage effort [Source: Symantec]
Microsoft would only comment, "We are working diligently to address this issue and will release a security update for customers."
A Knowledge Base (KB) page on the worm can be found
. It lists the worm's threat level as "severe".
II. Worm Targets U.S. Allies
Symantec Corp. (
) is among the firms tracking Duqu. Interestingly, they make some statements about the worm's origin which seemingly exonerate the U.S. from Stuxnet suspicions. Symantec states that the Duqu authors must have either been given code by the Stuxnet authors, have stolen the code from the Stuxnet authors, or
themselves the Stuxnet authors.
Symantec's Kevin Haley
, "We believe it is the latter."
The sophistication of this worm suggests that if the U.S. didn't have a hand in crafting it, that China or Russia perhaps did. A command and control server was found to be hosted in Belgium, but it's rather unlikely that the attackers chose their home nation to host the attacking platform.
a cyber-superpower and notorious aggressor
-- is thought to maintain a repository of unpublished vulnerabilities on platforms such as Windows, Linux, and OS X, waiting to exploit them when the need arises.
Nine international organizations have found their systems compromised. The compromised nations in these victim organizations are:
Organization A - France, Netherlands, Switzerland, Ukraine
Organization B - India
Organization C - Iran
Organization D - Iran
Organization E - Sudan
Organization F - Vietnam
Other researchers report that systems in the United Kingdom, Austria, Hungary, and Indonesia were infected.
"It seems as though my state-funded math degree has failed me. Let the lashings commence." -- DailyTech Editor-in-Chief Kristopher Kubicki
U.S. Suspects Chinese Involvement in Satellite Hacks; China Denies Accusations
October 31, 2011, 12:06 PM
Iran Say it Has Captured "Western Spies" Involved in Nuclear Cyberattack
October 5, 2010, 11:29 AM
Israel Suspected in Worm Sabotage of Iran's First Nuclear Plant
September 27, 2010, 10:45 AM
Netflix took a decision to invest in original content
January 19, 2017, 7:00 AM
Amazon Airborne Fulfillment Center – Your Merchandise Drop-Shipped from the Clouds
December 29, 2016, 5:00 AM
Amazon is experimenting with a new kind of grocery stores, Amazon Go
December 8, 2016, 5:00 AM
Google has developed Deep Learning Algorithm to detect Diabetic Eye Disease
December 4, 2016, 5:00 AM
Google plans ultra-fast wireless Internet for Research Triangle Park, N.C.
August 12, 2016, 6:30 AM
Twitter Senior VP: "Diversity is Important, But We Can’t Lower the Bar"
November 9, 2015, 9:59 AM
Most Popular Articles
Super Hi- Vision Will Amaze the World
January 16, 2017, 9:53 AM
Comparison: Xiaomi Mi Mix Vs. HTC U Ultra
January 14, 2017, 12:10 AM
A Few Technology Trends, Highlight’s of 2017
January 14, 2017, 12:31 AM
Gionee Marathon M5 Plus – China’s Flagship Smartphone
January 15, 2017, 2:02 AM
Samsung Chromebook Plus – Coming in February 2017
January 17, 2017, 12:01 AM
Latest Blog Posts
Jan 20, 2017, 7:00 AM
News of the World
Jan 19, 2017, 7:00 AM
News of the Day Wednesday 1/18/2017
Jan 18, 2017, 12:01 AM
Jan 17, 2017, 12:16 AM
News of the Day
Jan 16, 2017, 12:10 PM
News and Technology Advancement
Jan 16, 2017, 7:58 AM
Jan 15, 2017, 12:32 AM
Here is Some News
Jan 14, 2017, 12:39 AM
News: Improved and New products
Jan 13, 2017, 12:01 AM
News around the world
Jan 12, 2017, 12:01 AM
Rumors and Announcements
Jan 11, 2017, 12:01 AM
This year CES and ridiculous gadgets
Jan 10, 2017, 12:01 AM
Nokia Android phone spurns the west.
Jan 9, 2017, 12:08 AM
New at CES 2017 - Changhong 8K Super Slim TV 65ZHQ3R
Jan 8, 2017, 1:07 AM
Debuted at CES 2017 - Vuzix Blade 3000 Smart Sunglasses
Jan 8, 2017, 12:39 AM
Some news of Day
Jan 7, 2017, 12:01 AM
News 2017 CES
Jan 6, 2017, 12:01 AM
Here is the Latest News in Tech
Jan 5, 2017, 1:47 AM
AI Beats World’s Best at Chinese board game “Go”
Jan 4, 2017, 11:21 AM
Las Vegas 2017 CES
Jan 3, 2017, 12:01 AM
More Blog Posts
Copyright 2017 DailyTech LLC. -
Terms, Conditions & Privacy Information