Next Stuxnet? -- ICS-CERT Releases Alert On Duqu

ShareThis

Information about a worm very similar to Stuxnet has been released by the Industrial Control System - Cyber Emergency Response Team (ICS-CERT) in an Industry Alert. This threat has been named "Duqu" because it creates files with the file name prefix "~DQ".

Initial findings suggest that Duqu's purpose is to gather intelligence data and assets from entities, such as industrial control system manufacturers, with the intention to easily conduct a future attack against another third party. The creators of the code are looking for information such as design documents that could help them mount a future attack on an industrial control facility. Symantec has labelled this threat the “Precursor to the Next Stuxnet” based on some similarities between the two, and also released a Mitigation Fact Sheet.

UTC TELECOM 2012 Conference