Advertisement

Duqu attackers wiped Linux C&C servers

The Duqu malware has been creating havoc in the industrial sector across the world. The Indian officials had shut down ...

Advertisement
Naina Khedekar|Dec 01, 2011, 11:32:58 IST
The Duqu malware has been creating havoc in the industrial sector across the world. The Indian officials had shut down a server linked to Duqu in Mumbai, which was later taken under the hood for further investigation. The malicious was also fixed temporarily by Microsoft. The researchers from Kaspersky Lab who have been studying the Command and Control infrastructure by Duqu, have now revealed in a report that these attackers have made some critical mistakes with an attempt to clear evidence.Kaspersky report

Kaspersky report (Image Credit: Securelist)

The researchers showed that DuQu C&C servers were operated since November 2009. Most of the hacked machines were running on CentOS Linux. The attackers updated OpenSSH 4.3 to version 5 after gaining control each time. The report says, “Unfortunately, the most interesting server, the C&C proxy in India, was cleaned only hours before the hosting company agreed to make an image. If the image had been made earlier, it’s possible that now we’d know a lot more about the inner workings of the network.

Advertisement

According to the report, attackers took up a global cleanup operation on the various several Linux servers, which were used to control systems infected with DuQu on October 20. This was attempted on systems running on CentOS 5.x, just two days after the Duqu was compared publicly with Stuxnet. It is speculated that the operators were trying to cover their tracks. This was possibly done in a hurry, which led to the attackers making a critical mistake, as servers in Vietnam and Germany have partial logs of the hackers’ SSH.

news-analysisMore from News Analysis

The sshd.log files displayed that the attackers had logged into a Vietnam-based machine in July and in October, while they logged into a Germany-based system in as early as November 23, 2009. The servers were proxies which were designed to cover up attackers’ location. The real Duqu mothership C&C server and of course the identity of attackers isn’t disclosed yet.

Advertisement
Handpicked stories, in your inbox
Global stories. Indian perspective. Zero noise.
No Spam. Unsubscribe Any Time.

Armed with a Bachelor of Electronics Engineering degree, it is writing where Naina finds her calling. She has got her finger on the pulse of what's new and trending in the world of technology, right from gadgets to innovations. When she isn't hammering away on her keyboard, she is busy looking for figurines to add to her growing collection of Kinder toys. It doesn't get more diverse than that.

First Published:Dec 01, 2011, 11:32:58 IST
Advertisement
Advertisement
Trending Stories

China's Kimi K3 challenges US AI leaders with frontier-level performance at lower cost

Chinese artificial intelligence startup Moonshot AI has unveiled its latest open-weight AI model, Kimi K3, with early results suggesting it could compete with some of the world's most advanced AI systems developed by leading US companies
2 min read
Advertisement
Advertisement
Up Next