Follow Us

Duqu hackers wipe all servers going back to 2009

Hacker group shut down operation, all files and logs just days after researchers revealed botnet's existence

The hackers behind the Duqu botnet have shut down their snooping operation, a security researcher said today.

The 12 known command-and-control (C&C) servers for Duqu were scrubbed of all files on 20 October, 2011, according to Moscow-based Kaspersky Lab.

That was just two days after rival antivirus firm Symantec went public with its analysis of Duqu, a Trojan horse-based botnet that many security experts believe shared common code and characteristics with Stuxnet, the super-sophisticated worm that last year sabotaged Iran's nuclear program.

Duqu was designed, said Symantec and Kaspersky, by advanced hackers, most likely backed by an unknown country's government. Unlike Stuxnet, it was not crafted to wreak havoc on uranium enrichment centrifuges, but to scout out vulnerable installations and computer networks as a lead-in to the development of another worm targeting industrial control systems.

"I think this part of the [Duqu] operation is now closed." said Roel Schouwenberg, a Kaspersky senior researcher, in an emailed reply to questions today. "[But] that's not to say a new/modified operation may be under way."

Each variant used a different server

Earlier Wednesday, another Kaspersky expert posted an update on the company's investigation into Duqu that noted the hackers' house-cleaning.

According to Kaspersky, each Duqu variant - and it knows of an even dozen - used a different compromised server to manage the PCs infected with that specific version of the malware. Those servers were located in Belgium, India, the Netherlands and Vietnam, among other countries.

"The attackers wiped every single server they had used as far back as 2009," Kaspersky said, referring to the aforementioned cleaning job.

The hackers not only deleted all their files from those systems, but double-checked afterward that the cleaning had been effective, Kaspersky noted. "Each [C&C server] we've investigated has been scrubbed," said Schouwenberg.

Kaspersky also uncovered clues about Duqu's operation that it has yet to decipher.

The attackers quickly updated each compromised server's version of OpenSSH - for Open BSD Secure Shell, an open-source toolkit for encrypting Internet traffic - to a newer edition, replacing the stock 4.3 version with the newer 5.8.

Although there have been reports that OpenSSH contains an unpatched, or "zero-day," vulnerability - perhaps exploited by the Duqu hackers to hijack legitimate servers for their own use - Kaspersky eventually rejected that theory, saying it was simply "too scary" to contemplate.

Protecting stolen servers from other criminals

Even so, it was one of two reasons Schouwenberg proposed for the fast update to OpenSSH 5.8.

"The logical assumption here is that we're looking at possibly a vulnerability in the older version and/or an added feature in the new version that's of use to the attacker," said Schouwenberg.

By updating OpenSSH from the possibly-vulnerable OpenSSH 4.3, the Duqu developers may have intended to ensure that other criminals couldn't steal their stolen servers.

Iran, which last year acknowledged some systems, including ones in its nuclear facilities, had been infected with Stuxnet, two weeks ago admitted Duqu had also wiggled its way onto PCs in the country.

Duqu has been traced to attacks in several countries other than Iran, including the Sudan, and may have been under construction since August 2007.






Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Desktop modernisation

On the one hand, there is the need to keep the existing desktop environment efficient, secure...

Download Whitepaper

Top 10 myths about virtualising business-critical applications

Even though virtualization has brought positive change to enterprise IT over the last decade,...

Download Whitepaper

Aligning CFO and CIO priorities

Forward-thinking organisations are viewing cloud computing as an investment in business...

Download Whitepaper

The new corporate network

Businesses can’t afford to have employee productivity suffer because they cannot use their...

Download Whitepaper

Techworld UK - Technology - Business

Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...
LogMeIn Rescue

Accelerate Your IT Efficiency

View the latest capacity management resources including whitepapers, videos and news.

Find out more...

Site Map

* *