FYI.

This story is over 5 years old.

Tech

Duqu Nukem: Oh, Look, More Malware In Iran

Hey, remember "Duqu":http://motherboard.tv/2011/10/19/duqu-stuxnet-s-zombie-cousin-is-coming-for-our-data, that data-lifting Trojan detected on some European computer systems last month? You know, the bug that security firm Symantec "called":http://www...

Hey, remember Duqu, that data-lifting Trojan detected on some European computer systems last month? You know, the bug that security firm Symantec called a sort of zombie-like "precursor to the next Stuxnet"?

Well, it's just surfaced in Iran.

Gholamreza Jalali, head of Iran's civil defense organization, said Sunday that Tehran is "in the initial phase of fighting the Duqu virus," as Reuters reports, and that a "final report which says which organizations the virus has spread to and what its impacts are" has not yet been completed. Jalali added that at-risk computers at all critical sites are under inspection and that Iran, now squarely on both the cyber-offensive and defensive, has developed and deployed software to battle Duqu.

Advertisement

Together with Stuxnet and Stars, this recon-heavy bit of malware is the third virus in the past year flagged for having made landfall in Iran, whose nuclear enrichment facilities were originally cross haired by Stuxnet. There's no telling yet whether Stars is also akin to Stuxnet but, perhaps curiously, Western anti-virus firms haven't been able to get their hands on Stars samples, leading some to color that bit of malware as nothing more than a propaganda ploy by Tehran.

But whatever Stars' deal, it's impossible to see Duqu as something that was cooked up and launched from within Iranian borders, even as the bug wipes itself from infected systems after only 36 days. Why? Because it's tough to not see the "precursor to the next Stuxnet" as but another unrestrained marker of increasingly harried cyber relations in the Middle East.

Look. The Jewish state, pressing hard as it is for more sanctions on Iran after last week's damning U.N. report on Iran's nuclear ambitions, totally didn’t blow up an Iranian weapons depot over the weekend, or anything. (Iran says the explosion was an accident. Their bad.) And Iran? They totally didn’t hack numerous Israeli government websites last week or anything, either.

May we never see the day that Duqu morphs into a bigger, badder variant: Nuqu.

CONNECTIONS:

Reach this writer at brian@motherboard.tv.

Top image via AP