Skip to main content

Kaspersky: Stuxnet and Duqu had same developers, started as early as 2007

IranUranium
Image used with permission by copyright holder

The Stuxnet worm may go down in history as one of the first known instances of cyber warfare, since it appears to have been crafted specifically to disrupt Iran’s ambitions to refine weapons-grade uranium. Earlier this year, the related Duqu worm appeared—although it appears to have a different, unknown purpose. Although there has been speculation that Stuxnet and Duqu are related, Kaspersky security researcher Alexander Gostev says the two worms have to have been developed by the same team—and they may have gotten started as early as 2007.

Recommended Videos

“There were a number of projects involving programs based on the ‘Tilded’ platform throughout the period 2007-2011,” Gostav wrote. “Stuxnet and Duqu are two of them—there could have been others, which for now remain unknown.”

Researches refer to the worm platform as “Tilded” because of the authors’ propensity for starting file names with “~d.” But the similarities are much deeper, with the worms sharing the same fundamental architecture. Through analyzing drivers—including some unusual (and potentially unique) finds associated with Duqu infections—Kaspersky concludes the platform got started as a single-driver effort in 2007 or 2008, and got its most significant modifications in mid-2010. Kaspersky’s analysis also concludes there was “at least” on other spyware module built on the same platform back in 2007 or 2008.

Duqu/Stuxnet evolution
Image used with permission by copyright holder

The Stuxnet worm set off a frenzy of speculation amongst security researchers because of its complexity. Where most malware packages together a small set of functions around a small set of exploits so they can get into the wild quickly, Stuxnet contains more than 4,000 functions and functionality specifically targeting industrial control equipment—in fact, Stuxnet is so specific that it likely was crafted only to target Iran’s nuclear enrichment facilities. Duqu sports a similar complexity, and researchers at the Budapest University of Technology and Economics CrySyS lab (who discovered Duqu) speculate it is designed to steal industrial control design materials.

Some industry watchers have speculated that Stuxnet and Duqu may be the work of state-sponsored malware development efforts, with Israel and the United States often considered possible sources for the Stuxnet worm.

Geoff Duncan
Former Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
This Alienware x16 R2 gaming laptop with RTX 4080 is $700 off today
The Alienware x16 R2 gaming laptop with Evil Dead The Game on the screen.

You need to be ready to spend a lot of money if you want a powerful gaming laptop, but you should also be on the lookout for opportunities at huge savings from gaming laptop deals. Here's an offer that serious gamers should consider: the Alienware x16 R2 with the Nvidia GeForce RTX 4080 graphics card at $700 off from Dell, bringing its price down from $3,200 to $2,500. It's still pretty expensive, but you can't ignore that massive discount. This is a clearance sale though, so you need to hurry with your purchase because stocks of the gaming laptop may already be running low.

Why you should buy the Alienware x16 R2 gaming laptop

Read more
This compact HP Omen gaming PC is on sale at 39% off today
The HP Omen 16L gaming desktop sitting on a desk.

For those who want a proper gaming desktop but don't have enough space for a big and bulky machine, the HP Omen 16L could be what you need. You're in luck because it's on sale from the gaming PC deals of HP right now, with this configuration featuring the Nvidia GeForce RTX 3050 graphics card available at 39% off. You'll only have to pay $800 instead of its original price of $1,330, but you need to push through with your purchase immediately if you want to make sure you pocket the savings of $530.

Why you should buy the HP Omen 16L gaming PC

Read more
SpaceX’s Starlink rival is about to launch more internet satellites — here’s how to watch
Amazon's KA-01 mission for Project Kuiper gets underway from the Space Coast.

[UPDATE: A technical issue with the rocket has caused the launch to be postponed. We'll update this article with the new launch schedule just as soon as it becomes available.]

Amazon is preparing to launch its second batch of Project Kuiper internet satellites to orbit as it seeks to build out a constellation to take on SpaceX’s Starlink service.

Read more