Microsoft software bug linked to 'Duqu' virus

Tue Nov 1, 2011 5:21pm EDT

* Microsoft says working to fix bug, issue update

* Symantec says virus delivered via tainted Word document

* Details emerge as experts race to unlock Duqu secrets

Nov 1 (Reuters) - Microsoft Corp said hackers exploited a previously unknown bug in its Windows operating system to infect computers with the Duqu virus, which some security experts say could be the next big cyber threat.

"We are working diligently to address this issue and will release a security update for customers," Microsoft said on Tuesday in a short statement.

News of Duqu surfaced in October when security software maker Symantec Corp said it had found a mysterious computer virus that contained code similar to Stuxnet, a piece of malicious software believed to have wreaked havoc on Iran's nuclear program.

Government and private investigators around the world are racing to unlock the secret of Duqu, with early analysis suggesting that it was developed by sophisticated hackers to help lay the groundwork for attacks on critical infrastructure such as power plants, oil refineries and pipelines.

Details on how Duqu got onto infected machines emerged for the first time on Tuesday as Microsoft disclosed its link to the infection.

Separately, Symantec researchers said they believe hackers sent the virus to targeted victims via emails with tainted Microsoft Word documents attached.

If a recipient opened the Word document and infected the PC, the attacker could take control of the machine and reach into an organization's network to propagate itself and hunt for data, Symantec researcher Kevin Haley told Reuters.

He said some of the source code used in Duqu was also used in Stuxnet, a cyber weapon believed to have crippled centrifuges that Iran uses to enrich uranium.

That suggests that the attackers behind Stuxnet either gave that code to the developers of Duqu, allowed it to be stolen, or are the same people who built Duqu, Haley said.

"We believe it is the latter," he said.

Related Quotes and News

Company
Price
Related News
We welcome comments that advance the story through relevant opinion, anecdotes, links and data. If you see a comment that you believe is irrelevant or inappropriate, you can flag it to our editors by using the report abuse links. Views expressed in the comments do not represent those of Reuters. For more information on our comment policy, see http://blogs.reuters.com/fulldisclosure/2010/09/27/toward-a-more-thoughtful-conversation-on-stories/
Comments (1)
boldi wrote:
Would You be so kind to add reference to the www.crysys.hu CrySyS Lab Who identified the dropper?

Nov 01, 2011 5:35pm EDT  --  Report as abuse
This discussion is now closed. We welcome comments on our articles for a limited period after their publication.