Duqu: Precursor to the Next Stuxnet

    Antonio Forzieri
    Security Practice Manager – Technology Sales Organization

Duqu: Precursor to the Next Stuxnet                             1
Before starting…

                             Twitter
                             • You can follow our webinar on twitter in realtime.
                               Our twitter account is @StopBlackMarket




Duqu: Precursor to the Next Stuxnet
Before Starting…

                             Facebook
                             • You can follow us also on Facebook. Out
                               account is Stop Black Market




Duqu: Precursor to the Next Stuxnet
Before Staring…

                             Symantec
                             • You can access to all documents used for our webinars.
                               Our portal is http://www.symantec.it/blackmarket




Duqu: Precursor to the Next Stuxnet
Stuxnet
June 2010




Duqu: Precursor to the Next Stuxnet   5
Stuxnet
July 2010



                   www.premierfutbol.com




                                           www.todaysfutbol.com



Duqu: Precursor to the Next Stuxnet                               6
Stuxnet
               Geographic Distribution of Infections
                                    70,00



                                    60,00   58,31



                                    50,00
Unique IPs Contact C&C Server (%)




                                    40,00



                                    30,00


                                                      17,83
                                    20,00


                                                                9,96
                                    10,00
                                                                                                                                                 5,15
                                                                           3,40
                                                                                     1,40       1,16     0,89      0,71       0,61     0,57
                                     0,00
                                            IRAN    INDONESIA   INDIA   AZERBAIJAN PAKISTAN   MALAYSIA   USA    UZBEKISTAN   RUSSIA    GREAT    OTHERS
                                                                                                                                      BRITAIN


                                            Over 40,000 infected unique external IPs, from over 115 countries
               Duqu: Precursor to the Next Stuxnet                                                                                                       7
Stuxnet
November 2010

   S7-315 CPU                                CP-342-5 – 6 modules

                                                                           ...



          31 Vacon or Fararo Paya frequency converters per module


                                      ...                      ...

                                       ...                      ...

                                               Totaling up to 186 motors

Duqu: Precursor to the Next Stuxnet                                              8
Stuxnet
February 2011

• Symantec identified 5 domains as the target of Stuxnet
• All targets have a presence in Iran



       5 Domains targeted
      1800 domains infected




Duqu: Precursor to the Next Stuxnet                        9
Stuxnet Runs Its Course
• Stuxnet files date between June 2009 and March 2010
• After March 2010 no new Stuxnet files appeared in wild
• But it changed many things




Duqu: Precursor to the Next Stuxnet                        10
Stuxnet accomplished its mission




Duqu: Precursor to the Next Stuxnet   11
Limited internet access
                                      • Financial networks
                                        – E.g., ATMs, POS, SWIFTNet
                                      • Engineering networks
                                        – E.g., source code, design documents,
                                          non-production code
 Secure/No network access             • Classified data networks
                                      • Aviation & air traffic control systems
                                      • Life critical and healthcare systems
                                      • Law enforcement database networks
                                      • Military communication systems
                                      • Malware analysis networks



Duqu: Precursor to the Next Stuxnet                                        12
This changes everything…




Duqu: Precursor to the Next Stuxnet   13
Much more can happen




Duqu: Precursor to the Next Stuxnet   14
Stuxnet




Duqu: Precursor to the Next Stuxnet   15
Duqu


                                      • October 14th research lab
                                        reached out to Symantec to
                                        confirm a suspicion on newly
                                        discovered threat
                                      • We confirmed their suspicion
                                      • This threat uses source code
                                        from Stuxnet




Duqu: Precursor to the Next Stuxnet                                    16
Duqu: Key Facts
• New executables using Stuxnet source code have been discovered
   – Developed since the last Stuxnet file was recovered


• New executables designed to capture information like keystrokes
  & system information


• Current analysis shows no code related to industrial control systems,
  exploits, or self-replication


• Executables found in limited number of organizations
   – Including those involved in the manufacturing of industrial control systems


• Exfiltrated data may be used to enable a future Stuxnet-like attack


Duqu: Precursor to the Next Stuxnet                                                17
Source Code

             Stuxnet




Duqu: Precursor to the Next Stuxnet   18
Source Code

             Stuxnet

                    Duqu




Duqu: Precursor to the Next Stuxnet   19
Stuxnet
Extensive Infection Vectors
                                                     Network
                                                      Shares

                           
                                                     Print
                                                      Spooler
                                                      (MS10-061)

                                                     SMB
                                                    (MS08-067)

                   Step7              WinCC SQL      P2P
                                                      (Updating only)




Duqu: Precursor to the Next Stuxnet                                     20
Duqu
Infection Vectors




Duqu: Precursor to the Next Stuxnet   21
Duqu
Deception




Duqu: Precursor to the Next Stuxnet   22
Duqu
Deception




                                      36 days

Duqu: Precursor to the Next Stuxnet         23
Stuxnet
Deception

• 2 stolen private
  keys used to sign
  the application
  to allow
  undetected
  installation of
  rootkits




Duqu: Precursor to the Next Stuxnet   24
Duqu
Deception




         A stolen private key used to sign the application
            to allow undetected installation of rootkits




Duqu: Precursor to the Next Stuxnet                          25
Stuxnet
Reconnaissance
    Limited internet access
                                                                    Attacker



                                                    www.mypremierfutbol.com
                                                     www.todaysfutbol.com

                                      • Infected machines check in with system
                                        information
                                         – OS version
                                         – Computer name
                                         – Domain
                                         – IP addresses
                                         – Configuration data
                                         – Existence of ICS programming software (STEP7)
                                      • And will send design documents if requested

Duqu: Precursor to the Next Stuxnet                                              26
Duqu
Reconnaissance
    Limited internet access
                                                                Attacker



                                                    206.[REMOVED].97


                                      • Download Infostealer to gather:
                                        – Running processes, account details,
                                          domains
                                        – Driver names, shared drive info, etc
                                        – Screenshots
                                        – Keystrokes
                                        – Network information
                                      • Every 30 seconds

Duqu: Precursor to the Next Stuxnet                                          27
Duqu
Target
    Limited internet access
                                                         Attacker
                                      • Limited in number
                                      • In Europe
                                      • Involved in manufacturing
                                        of industrial control systems


                                      • We have found an
                                        additional variant since we
                                        went public
                                       The compilation time on the
                                           code was 10/17/2011

Duqu: Precursor to the Next Stuxnet                                 28
Symantec Customers Are Protected
• Those with updated AV
  definitions
• Those using Insight
  technology in SEP 12.1
    – Low prevalence of Duqu




Duqu: Precursor to the Next Stuxnet   29
Recommended Defenses
          Advanced Reputation Techniques
          • Duqu is extremely targeted and thus, would have a low reputation profile

          Host Intrusion Prevention Systems
          • Implements host-lock-down as a means of hardening against malware infiltration

          Removable Media Device Control
          • Many infection vectors appear to be delivered by removable media
          • Restrict automatic launch of content on removable media

          Data Loss Prevention
          • Core repositories of intellectual property are likely prequel targets on Enterprise LAN

          Automated Compliance Monitoring
          • Detecting default passwords on industrial control systems

Duqu: Precursor to the Next Stuxnet                                                                   30
What to Do?


    1            Stay Current
                 on latest Duqu research with Twitter.com/threatintel




    2            Stay Informed
                 on Symantec’s outbreak page at www.symantec.com/outbreak




    3            Contact
                 Ask us for a Malicious Activity Assessment



Duqu: Precursor to the Next Stuxnet                                         31
Thank you!




    Copyright © 2011 Symantec Corporation. All rights reserved. Symantec and the Symantec Logo are trademarks or registered trademarks of Symantec Corporation or its affiliates in
    the U.S. and other countries. Other names may be trademarks of their respective owners.

    This document is provided for informational purposes only and is not intended as advertising. All warranties relating to the information in this document, either express or implied,
    are disclaimed to the maximum extent allowed by law. The information in this document is subject to change without notice.


Duqu: Precursor to the Next Stuxnet                                                                                                                                                         32

More Related Content

PDF
Aleksandr Matrosov, Eugene Rodionov - Win32 Duqu - involution of Stuxnet
PDF
PPTX
Stuxnet mass weopan of cyber attack
PPSX
Stuxnet - More then a virus.
PDF
A Stuxnet for Mainframes
PPT
Stuxnet flame
PDF
Win32/Flamer: Reverse Engineering and Framework Reconstruction
PDF
The Duqu 2.0: Technical Details
Aleksandr Matrosov, Eugene Rodionov - Win32 Duqu - involution of Stuxnet
Stuxnet mass weopan of cyber attack
Stuxnet - More then a virus.
A Stuxnet for Mainframes
Stuxnet flame
Win32/Flamer: Reverse Engineering and Framework Reconstruction
The Duqu 2.0: Technical Details

Viewers also liked (6)

PPT
Cours CyberSécurité - Concepts Clés
PDF
Sécurité des systèmes d'information
PDF
Cyber Sécurité : Connaître son adversaire pour mieux parer les attaques
PPTX
Principes de bon sens pour une gouvernance cyber sécurité efficiente
PPSX
La securité informatique - Etat des Lieux - Nov. 2016
PPTX
Sécurité informatique
Cours CyberSécurité - Concepts Clés
Sécurité des systèmes d'information
Cyber Sécurité : Connaître son adversaire pour mieux parer les attaques
Principes de bon sens pour une gouvernance cyber sécurité efficiente
La securité informatique - Etat des Lieux - Nov. 2016
Sécurité informatique
Ad

Similar to Duqu: il nuovo Stuxnet? (20)

PPT
The 1-hour Guide to Stuxnet.ppt
PDF
Mission Critical Security in a Post-Stuxnet World Part 1
PPTX
Infrastructure Attacks - The Next generation, ESET LLC
PDF
SDARPiBot - VLES'16
PDF
Quantum Hardware Hacking
DOCX
Kumar cscl final
PDF
Defcon 22-cesar-cerrudo-hacking-traffic-control-systems
PPTX
BSides London 2015 - Proprietary network protocols - risky business on the wire.
PDF
Stuxnet
PDF
Cisco connect winnipeg 2018 stealthwatch whiteboard session and cisco secur...
PDF
Test Execution Infrastructure for IoT Quality analysis
PDF
Stuxnet - A weapon of the future
PPTX
Analysis of exposed ICS//SCADA/IoT systems in Europe
PDF
Optional Reading - Symantec Stuxnet Dossier
PPTX
Mistral and StackStorm
PDF
Messaging for the Internet of Awesome Things
ODP
Challenges and experiences with IPTV from a network point of view
PPTX
Enhance Virtual Machine Security in OpenStack Using Suricata IPS
PPTX
Black Hat USA 2022 - Arsenal Labs - Vehicle Control Systems - Red vs Blue
PPT
IDS-ETHZ - NSG-IDS-REPORTING_of_year_2015
The 1-hour Guide to Stuxnet.ppt
Mission Critical Security in a Post-Stuxnet World Part 1
Infrastructure Attacks - The Next generation, ESET LLC
SDARPiBot - VLES'16
Quantum Hardware Hacking
Kumar cscl final
Defcon 22-cesar-cerrudo-hacking-traffic-control-systems
BSides London 2015 - Proprietary network protocols - risky business on the wire.
Stuxnet
Cisco connect winnipeg 2018 stealthwatch whiteboard session and cisco secur...
Test Execution Infrastructure for IoT Quality analysis
Stuxnet - A weapon of the future
Analysis of exposed ICS//SCADA/IoT systems in Europe
Optional Reading - Symantec Stuxnet Dossier
Mistral and StackStorm
Messaging for the Internet of Awesome Things
Challenges and experiences with IPTV from a network point of view
Enhance Virtual Machine Security in OpenStack Using Suricata IPS
Black Hat USA 2022 - Arsenal Labs - Vehicle Control Systems - Red vs Blue
IDS-ETHZ - NSG-IDS-REPORTING_of_year_2015
Ad

More from Symantec Italia (20)

PDF
Il Cloud a difesa della mail e del web
PDF
Garantire la confidenzialità delle informazioni: la soluzione PGP per l'Encry...
PDF
Le minacce, le tecniche di attacco e i canali di vendita delle informazioni
PDF
Spam and Phishing Report - Marzo 2010
PDF
Backup Exec 2010: la matrice di prodotto
PDF
Symantec Backup Exec 2010 per Windows Small Business Server
PDF
Backup Exec 2010. Domande frequenti
PDF
Symantec Backup Exec 2010
PDF
Phishing Report Gennaio 2010
PDF
Spam Report Gennaio 2010
DOC
Storage: le Tendenze per il 2010
DOC
Sicurezza Internet: tendenze e previsioni 2010
PDF
Symantec Backup Exec System Recovery 2010
PDF
Phishing Report Novembre 2009
PDF
Report on Rogue Security Software: a summary
PDF
Report on Rogue Security Software
PDF
Smb Disaster Preparedness Survey Italia
PDF
I primi dieci vantaggi di Symantec Protection Suite e i primi dieci motivi pe...
PDF
Symantec Endpoint Protection: la tecnologia Antivirus Symantec di nuova gener...
PDF
Symantec Internet Security Threat Report, Volume XIV
Il Cloud a difesa della mail e del web
Garantire la confidenzialità delle informazioni: la soluzione PGP per l'Encry...
Le minacce, le tecniche di attacco e i canali di vendita delle informazioni
Spam and Phishing Report - Marzo 2010
Backup Exec 2010: la matrice di prodotto
Symantec Backup Exec 2010 per Windows Small Business Server
Backup Exec 2010. Domande frequenti
Symantec Backup Exec 2010
Phishing Report Gennaio 2010
Spam Report Gennaio 2010
Storage: le Tendenze per il 2010
Sicurezza Internet: tendenze e previsioni 2010
Symantec Backup Exec System Recovery 2010
Phishing Report Novembre 2009
Report on Rogue Security Software: a summary
Report on Rogue Security Software
Smb Disaster Preparedness Survey Italia
I primi dieci vantaggi di Symantec Protection Suite e i primi dieci motivi pe...
Symantec Endpoint Protection: la tecnologia Antivirus Symantec di nuova gener...
Symantec Internet Security Threat Report, Volume XIV

Recently uploaded (20)

PDF
Rapid Prototyping: A lecture on prototyping techniques for interface design
PDF
Advancing precision in air quality forecasting through machine learning integ...
PDF
Auditboard EB SOX Playbook 2023 edition.
PDF
Transform-Your-Factory-with-AI-Driven-Quality-Engineering.pdf
PDF
zbrain.ai-Scope Key Metrics Configuration and Best Practices.pdf
PPTX
agenticai-neweraofintelligence-250529192801-1b5e6870.pptx
PPTX
MuleSoft-Compete-Deck for midddleware integrations
PDF
Planning-an-Audit-A-How-To-Guide-Checklist-WP.pdf
PDF
The-Future-of-Automotive-Quality-is-Here-AI-Driven-Engineering.pdf
PDF
Early detection and classification of bone marrow changes in lumbar vertebrae...
PDF
Transform-Quality-Engineering-with-AI-A-60-Day-Blueprint-for-Digital-Success.pdf
PDF
4 layer Arch & Reference Arch of IoT.pdf
PPTX
Microsoft User Copilot Training Slide Deck
PDF
EIS-Webinar-Regulated-Industries-2025-08.pdf
PPTX
AI-driven Assurance Across Your End-to-end Network With ThousandEyes
PDF
The-2025-Engineering-Revolution-AI-Quality-and-DevOps-Convergence.pdf
PDF
A hybrid framework for wild animal classification using fine-tuned DenseNet12...
PDF
The AI Revolution in Customer Service - 2025
PPTX
SGT Report The Beast Plan and Cyberphysical Systems of Control
PDF
A symptom-driven medical diagnosis support model based on machine learning te...
Rapid Prototyping: A lecture on prototyping techniques for interface design
Advancing precision in air quality forecasting through machine learning integ...
Auditboard EB SOX Playbook 2023 edition.
Transform-Your-Factory-with-AI-Driven-Quality-Engineering.pdf
zbrain.ai-Scope Key Metrics Configuration and Best Practices.pdf
agenticai-neweraofintelligence-250529192801-1b5e6870.pptx
MuleSoft-Compete-Deck for midddleware integrations
Planning-an-Audit-A-How-To-Guide-Checklist-WP.pdf
The-Future-of-Automotive-Quality-is-Here-AI-Driven-Engineering.pdf
Early detection and classification of bone marrow changes in lumbar vertebrae...
Transform-Quality-Engineering-with-AI-A-60-Day-Blueprint-for-Digital-Success.pdf
4 layer Arch & Reference Arch of IoT.pdf
Microsoft User Copilot Training Slide Deck
EIS-Webinar-Regulated-Industries-2025-08.pdf
AI-driven Assurance Across Your End-to-end Network With ThousandEyes
The-2025-Engineering-Revolution-AI-Quality-and-DevOps-Convergence.pdf
A hybrid framework for wild animal classification using fine-tuned DenseNet12...
The AI Revolution in Customer Service - 2025
SGT Report The Beast Plan and Cyberphysical Systems of Control
A symptom-driven medical diagnosis support model based on machine learning te...

Duqu: il nuovo Stuxnet?

  • 1. Duqu: Precursor to the Next Stuxnet Antonio Forzieri Security Practice Manager – Technology Sales Organization Duqu: Precursor to the Next Stuxnet 1
  • 2. Before starting… Twitter • You can follow our webinar on twitter in realtime. Our twitter account is @StopBlackMarket Duqu: Precursor to the Next Stuxnet
  • 3. Before Starting… Facebook • You can follow us also on Facebook. Out account is Stop Black Market Duqu: Precursor to the Next Stuxnet
  • 4. Before Staring… Symantec • You can access to all documents used for our webinars. Our portal is http://www.symantec.it/blackmarket Duqu: Precursor to the Next Stuxnet
  • 5. Stuxnet June 2010 Duqu: Precursor to the Next Stuxnet 5
  • 6. Stuxnet July 2010 www.premierfutbol.com www.todaysfutbol.com Duqu: Precursor to the Next Stuxnet 6
  • 7. Stuxnet Geographic Distribution of Infections 70,00 60,00 58,31 50,00 Unique IPs Contact C&C Server (%) 40,00 30,00 17,83 20,00 9,96 10,00 5,15 3,40 1,40 1,16 0,89 0,71 0,61 0,57 0,00 IRAN INDONESIA INDIA AZERBAIJAN PAKISTAN MALAYSIA USA UZBEKISTAN RUSSIA GREAT OTHERS BRITAIN Over 40,000 infected unique external IPs, from over 115 countries Duqu: Precursor to the Next Stuxnet 7
  • 8. Stuxnet November 2010 S7-315 CPU CP-342-5 – 6 modules ... 31 Vacon or Fararo Paya frequency converters per module ... ... ... ... Totaling up to 186 motors Duqu: Precursor to the Next Stuxnet 8
  • 9. Stuxnet February 2011 • Symantec identified 5 domains as the target of Stuxnet • All targets have a presence in Iran 5 Domains targeted 1800 domains infected Duqu: Precursor to the Next Stuxnet 9
  • 10. Stuxnet Runs Its Course • Stuxnet files date between June 2009 and March 2010 • After March 2010 no new Stuxnet files appeared in wild • But it changed many things Duqu: Precursor to the Next Stuxnet 10
  • 11. Stuxnet accomplished its mission Duqu: Precursor to the Next Stuxnet 11
  • 12. Limited internet access • Financial networks – E.g., ATMs, POS, SWIFTNet • Engineering networks – E.g., source code, design documents, non-production code Secure/No network access • Classified data networks • Aviation & air traffic control systems • Life critical and healthcare systems • Law enforcement database networks • Military communication systems • Malware analysis networks Duqu: Precursor to the Next Stuxnet 12
  • 13. This changes everything… Duqu: Precursor to the Next Stuxnet 13
  • 14. Much more can happen Duqu: Precursor to the Next Stuxnet 14
  • 15. Stuxnet Duqu: Precursor to the Next Stuxnet 15
  • 16. Duqu • October 14th research lab reached out to Symantec to confirm a suspicion on newly discovered threat • We confirmed their suspicion • This threat uses source code from Stuxnet Duqu: Precursor to the Next Stuxnet 16
  • 17. Duqu: Key Facts • New executables using Stuxnet source code have been discovered – Developed since the last Stuxnet file was recovered • New executables designed to capture information like keystrokes & system information • Current analysis shows no code related to industrial control systems, exploits, or self-replication • Executables found in limited number of organizations – Including those involved in the manufacturing of industrial control systems • Exfiltrated data may be used to enable a future Stuxnet-like attack Duqu: Precursor to the Next Stuxnet 17
  • 18. Source Code Stuxnet Duqu: Precursor to the Next Stuxnet 18
  • 19. Source Code Stuxnet Duqu Duqu: Precursor to the Next Stuxnet 19
  • 20. Stuxnet Extensive Infection Vectors  Network Shares   Print Spooler (MS10-061)  SMB   (MS08-067) Step7 WinCC SQL  P2P (Updating only) Duqu: Precursor to the Next Stuxnet 20
  • 21. Duqu Infection Vectors Duqu: Precursor to the Next Stuxnet 21
  • 22. Duqu Deception Duqu: Precursor to the Next Stuxnet 22
  • 23. Duqu Deception 36 days Duqu: Precursor to the Next Stuxnet 23
  • 24. Stuxnet Deception • 2 stolen private keys used to sign the application to allow undetected installation of rootkits Duqu: Precursor to the Next Stuxnet 24
  • 25. Duqu Deception A stolen private key used to sign the application to allow undetected installation of rootkits Duqu: Precursor to the Next Stuxnet 25
  • 26. Stuxnet Reconnaissance Limited internet access Attacker www.mypremierfutbol.com www.todaysfutbol.com • Infected machines check in with system information – OS version – Computer name – Domain – IP addresses – Configuration data – Existence of ICS programming software (STEP7) • And will send design documents if requested Duqu: Precursor to the Next Stuxnet 26
  • 27. Duqu Reconnaissance Limited internet access Attacker 206.[REMOVED].97 • Download Infostealer to gather: – Running processes, account details, domains – Driver names, shared drive info, etc – Screenshots – Keystrokes – Network information • Every 30 seconds Duqu: Precursor to the Next Stuxnet 27
  • 28. Duqu Target Limited internet access Attacker • Limited in number • In Europe • Involved in manufacturing of industrial control systems • We have found an additional variant since we went public The compilation time on the code was 10/17/2011 Duqu: Precursor to the Next Stuxnet 28
  • 29. Symantec Customers Are Protected • Those with updated AV definitions • Those using Insight technology in SEP 12.1 – Low prevalence of Duqu Duqu: Precursor to the Next Stuxnet 29
  • 30. Recommended Defenses Advanced Reputation Techniques • Duqu is extremely targeted and thus, would have a low reputation profile Host Intrusion Prevention Systems • Implements host-lock-down as a means of hardening against malware infiltration Removable Media Device Control • Many infection vectors appear to be delivered by removable media • Restrict automatic launch of content on removable media Data Loss Prevention • Core repositories of intellectual property are likely prequel targets on Enterprise LAN Automated Compliance Monitoring • Detecting default passwords on industrial control systems Duqu: Precursor to the Next Stuxnet 30
  • 31. What to Do? 1 Stay Current on latest Duqu research with Twitter.com/threatintel 2 Stay Informed on Symantec’s outbreak page at www.symantec.com/outbreak 3 Contact Ask us for a Malicious Activity Assessment Duqu: Precursor to the Next Stuxnet 31
  • 32. Thank you! Copyright © 2011 Symantec Corporation. All rights reserved. Symantec and the Symantec Logo are trademarks or registered trademarks of Symantec Corporation or its affiliates in the U.S. and other countries. Other names may be trademarks of their respective owners. This document is provided for informational purposes only and is not intended as advertising. All warranties relating to the information in this document, either express or implied, are disclaimed to the maximum extent allowed by law. The information in this document is subject to change without notice. Duqu: Precursor to the Next Stuxnet 32