The Jerusalem Post
Jpost search icon google-icon iphone
  Set as Homepage
Sat, May 25, 2013   16 Sivan, 5773
newspapers magazines
 
    • Breaking News
    • Diplomacy & Politics
    • Defense
    • National
    • Mideast
    • Syria
    • Iran
    • World
    • Business
    • Sports
    • Health & Science
    • Environment
  • Video
  • Opinion
    • Columnists
    • Editorials
    • Op-Eds
    • Letters
  • Jewish World
  • Lifestyle
    • Arts & Culture
    • Food & Wine
    • Travel
  • Features
    • Insights & Features
    • Week in review
    • On the Web
    • Shalva Superheroes
    • Obama in Israel
  • Blogs
    • In the news
    • Judaism
    • From the Middle East
    • Lifestyle
    • Aliya
    • Science and Technology
  • JPost Apps
    • iPhone app
    • iPad app
    • Android app
    • Twitter
    • Facebook
    • RSS feeds
    • JPost Toolbar
    • JPost Newsletter
    • JPost Alert
  • Premium Zone
    • The Jerusalem Report
    • The Experts
    • 20 Questions
    • e-paper
    • Ivrit
    • Christian Edition
    • Dash
    • Magazine
    • Metro
    • In Jerusalem
  • French
    • Politique & Social
    • Affaires Palestiniennes
    • Diplomatie & Monde
    • Art & Culture
    • Israel
  • Green Israel
JPost Learn Hebrew  
Advertise with us  
Nefesh Guided Aliyah  
Eldan  
AFMDA  
Africa Israel Group  
Isram Group  
Kupat Ha  
JPost Twitter  
JPost Facebook  
Classifieds  
         
 
 
    
Breaking News
 
 
  • JPost.com
  • Iranian Threat
  • News
 

'Stuxnet weapon has at least 4 cousins'

By REUTERS
LAST UPDATED: 12/29/2011 15:29
Tweet

Kaspersky security firm says virus that damaged Iran's nuke program 1 of at least 5 developed on a single platform.

Stuxnet Virus
Stuxnet Virus Photo: Courtesy
Security experts widely believe that the United States and Israel were behind Stuxnet, though the two nations have officially declined to comment on the matter.

A Pentagon spokesman on Wednesday declined comment on Kaspersky's research, which did not address who was behind Stuxnet.

RELATED:
Iran admits to Stuxnet-like virus infection
Ahmadinejad admits centrifuges damaged by virus

Stuxnet has already been linked to another virus, the Duqu data-stealing trojan, but Kaspersky's research suggests that the cyber weapons program that targeted Iran may be far more sophisticated than previously known.

Kaspersky's director of global research & analysis, Costin Raiu, told Reuters on Wednesday that his team has gathered evidence that shows the same platform that was used to build Stuxnet and Duqu was also used to create at least three other pieces of malware.

Raiu said the platform is comprised of a group of compatible software modules designed to fit together, each with different functions. Its developers can build new cyber weapons by simply adding and removing modules.

"It's like a Lego set. You can assemble the components into anything: a robot or a house or a tank," he said.

Kaspersky named the platform "Tilded" because many of the files in Duqu and Stuxnet have names beginning with the tilde symbol "~" and the letter "d."

Researchers with Kaspersky have not found any new types of malware built on the Tilded platform, Raiu said, but they are fairly certain that they exist because shared components of Stuxnet and Duqu appear to be searching for their kin.

When a machine becomes infected with Duqu or Stuxnet, the shared components on the platform search for two unique registry keys on the PC linked to Duqu and Stuxnet that are then used to load the main piece of malware onto the computer, he said.

Kaspersky recently discovered new shared components that search for at least three other unique registry keys, which suggests that the developers of Stuxnet and Duqu also built at least three other pieces of malware using the same platform, he added.

Those modules handle tasks including delivering the malware to a PC, installing it, communicating with its operators, stealing data and replicating itself.

Makers of anti-virus software including Kaspersky, U.S. firm Symantec Corp and Japan's Trend Micro Inc have already incorporated technology into their products to protect computers from becoming infected with Stuxnet and Duqu.

Click here for full Jpost coverage of the 































Iranian threat

Yet it would be relatively easy for the developers of those highly sophisticated viruses to create other weapons that can evade detection by those anti-virus programs through the modules in the Tilded platform, he said.

Kaspersky believes that Tilded traces back to at least 2007 because specific code installed by Duqu was compiled from a device running a Windows operating system on August 31, 2007.
  • Send
  • Large
  • Small
  • Print
  • Share
Most Viewed in
1
PM: Sanctions haven't stopped Iran’s nuclear quest
2
'Wave of cyber attacks on US originating in Iran'
3
Senate: US must back Israel in case of Iran strike
4
Senate resolution: US will back Israeli force on Iran
JPost Community
Tweet
Stuxnet Duqu virus Tilded Kaspersky Symantec Iran nuclear cyber
Share this article
Tweet
Share
Send
Your comment must be approved by a moderator before being published on JPost.com. Disqus users can post comments automatically.

Comments must adhere to our Talkback policy. If you believe that a comment has breached the Talkback policy, please press the flag icon to bring it to the attention of our moderation team.
JPost Services
conferenceConference
newsletterNewsletter
iphoneMobile Apps
kotelcamKotel Cam
kolboJPost Alert
premiumPremium
JPost TV News  
Mobile Apps  
Bank Hapoalim  
Meir Panim  
Yad Ezra  
Rambam Hospital  
TourLuxe  
Zev Goldstein PLLC  
Penrose Gallery  
JPost Premium Zone  
JPost kotel Camera  
         
 
Israel Focus
JPost TV News
Coming soon to a screen near you!  
Nefesh B'Nefesh Guided Aliyah
Already living in Israel? Enjoy the Benefits of Aliyah!  
Give "Freedom" this Passover
to needy Israeli families. Donate now  
War Threatens
Protect the People of Northern Israel  
China Suppliers
 
Intelligence Squared
The international debate forum, announces it is coming to Israel  
Bank Hapoalim
Israeli's number one bank  
Jerusalem Post Lite
Lite Edition of the Jerusalem Post for English improvement  
Learn Hebrew with us
Get 10 minutes free personal coaching in Hebrew through phone or Skype  
JPost newspapers
Sign up for the JPost newspapers and receive one month free subscription  
Kosher English Magazine
English language weekly magazine - especially for religious people  
JReport Kindle Edition
Now you can get the Jerusalem Report directly to your Kindle  
JPost Premium Edition
The very best articles are available only in our Premium edition  
Lifestyle Magazine
 
 
Real Estate
Don't Look For a House!
In Israel, our website will do it for you!  
 
Travel
Eldan Rent a Car
20% off all Car Rental Reservations in Israel  
Hertz Car Rental
Special Online Discounts!  
The King David Jerusalem Hotel
One of the world's truly iconic hotels, and a Jerusalem landmark  
 
 
 

Sites Of Interest:

Jerusalem Hotels
KKL-JNF
Poalim Online
BreitBart.com
Our Friends
Jerusalem Attractions
Jerusalem Tours
itraveljerusalem.com

JPost sites:

Learn Hebrew
The Jerusalem Report
Our Magazines
JPost Edition Francaise
Green Israel
Christian World
Jerusalem Post Lite

Services:

JPost Mobile Apps
JPost Premium
JPost Newsletter
JPost Toolbar
JPost News Ticker
JPost RSS feeds
JPost Archives
JPost Alert
JPost Kotel Cam

JPost Conferences:

NYC Conference
Diplomatic Conference

Information:

About Us
Feedback
Staff E-mails
Copyright
Sitemap
News Partners
Advertise with Us
Statistics
Ad Specs
Terms Of Service
Jpost.com, the online edition of the Jerusalem Post Newspaper - the most read and best-selling English-language newspaper in Israel. For analysis and opinion from Israel, the Jewish World and the Middle East. Jpost.com offers expert and in-depth reporting from Israel, the Jewish World and the Middle East, including diplomacy and defense, the Palestinian-Israeli conflict, the Arab Spring, the Mideast peace process, politics in Israel, life in Jerusalem, Israel's international affairs, Iran and its nuclear program, Syria and the Syrian civil war, Lebanon, the Palestinian Authority, the West Bank and Gaza Strip, Israel's world of business and finance, and Jewish life in Israel and the Diaspora.
 
About Us | Advertise with Us | Subscribe | Premium | Newsletter | RSS | Contact Us
 
All rights reserved © The Jerusalem Post 1995 - 2012