Pakistanis angry over detentions in Times Sq. case Monday, May 24, 2010
ISLAMABAD – Relatives of three men detained by Pakistan for alleged links to the suspect in the attempted Times Square bombing say the men are innocent.
They
AFP - Thursday, August 6TAIPEI (AFP) - - Taiwan's Beijing-friendly government on Wednesday denied boycotting an Australian film festival amid a row over the e
BERLIN (Reuters) - Chancellor Angela Merkel suffered a double blow on Thursday as a senior party ally in east German
Minister seeks closure of anti-Berlusconi websites Wednesday, December 16, 2009
ROME (AFP) - – The Italian government moved Tuesday to close down Internet sites encouraging further violence against Prime Minister Silvio Berlusconi, who
By ELAINE KURTENBACH,AP Business Writer AP - Wednesday, March 18SHANGHAI - Asia's stock market rally seemed to be running out of steam Wednesday, despite an
Edition:
U.S.
Africa
Arabic
Argentina
Brazil
Canada
China
France
Germany
India
Italy
Japan
Latin America
Mexico
Russia
Spain
United Kingdom
Home
Business
Business Home
Economy
Technology
Media
Small Business
Green Business
Legal
Deals
Earnings
Summits
Business Video
Markets
Markets Home
U.S. Markets
European Markets
Asian Markets
Global Market Data
Indices
M&A
Stocks
Bonds
Currencies
Commodities
Futures
Funds
peHUB
World
World Home
U.S.
Brazil
China
Euro Zone
Japan
Mexico
Russia
Afghan Journal
Africa Journal
India Insight
Global News Journal
Pakistan: Now or Never?
World Video
Politics
Politics Home
Front Row Washington
Politics Video
Technology
Technology Home
MediaFile
Science
Tech Video
Opinion
Opinion Home
Chrystia Freeland
Felix Salmon
John Lloyd
Jack Shafer
Breakingviews
David Rohde
Bernd Debusmann
Gregg Easterbrook
Nader Mousavizadeh
James Saft
David Cay Johnston
Edward Hadas
Hugo Dixon
Ian Bremmer
Mohamed El-Erian
Lawrence Summers
Susan Glasser
The Great Debate
Newsmaker
Money
Money Home
Analyst Research
Global Investing
MuniLand
Reuters Money Blog
John Wasik
Unstructured Finance
Alerts
Watchlist
Portfolio
Stock Screener
Fund Screener
Personal Finance Video
Life & Culture
Health
Sports
Arts
Faithworld
Business Traveler
Left Field
Entertainment
Oddly Enough
Lifestyle Video
Pictures
Pictures Home
Reuters Photographers
Full Focus
Video
Article
Comments (1)
Follow Reuters
Facebook
Twitter
RSS
YouTube
Read
ICC warns Libya's Saif al-Islam against fleeing
|
12:53am EDT
Cain's smoking ad divides Republicans: Reuters/Ipsos poll
28 Oct 2011
Google takes another shot at the TV market
|
28 Oct 2011
Cain's smoking ad divides Republicans: Reuters/Ipsos poll
28 Oct 2011
Generators taken from NY anti-Wall Street protesters
|
1:17am EDT
Discussed
293
Obama to announce help on housing, student loans
115
Two abortion clinic employees plead guilty to murder
91
Fraud case leaves California Democrats scrambling
Watched
New CPR technique revives man after 63 minutes without pulse
Thu, Oct 27 2011
Video purports to show Gaddafi capture
Mon, Oct 24 2011
Dueling demonstrations in Yemen
Fri, Oct 28 2011
India shuts server linked to Duqu computer virus
Tweet
Share this
Email
Print
Related News
Exclusive: NSA helps banks battle hackers
Wed, Oct 26 2011
UPDATE 3-Symantec forecasts sales below Street, shares drop
Wed, Oct 26 2011
Exclusive: National Security Agency helps banks battle hackers
Wed, Oct 26 2011
Analysis: Agreement seen distant at London cyber conference
Wed, Oct 26 2011
Exclusive: Medtronic probes insulin pump risks
Tue, Oct 25 2011
Analysis & Opinion
Tech wrap: Netflix shares plummet
Facebook makes us embrace creepy
Related Topics
Technology »
By Jim Finkle and Supantha Mukherjee
Fri Oct 28, 2011 6:41pm EDT
(Reuters) - Indian authorities seized computer equipment from a data center in Mumbai as part of an investigation into the Duqu malicious software that some security experts warned could be the next big cyber threat.
Two workers at a web-hosting company called Web Werks told Reuters that officials from India's Department of Information Technology last week took several hard drives and other components from a server that security firm Symantec Corp told them was communicating with computers infected with Duqu.
News of Duqu first surfaced last week when Symantec said it had found a mysterious computer virus that contained code similar to Stuxnet, a piece of malware believed to have wreaked havoc on Iran's nuclear program.
Government and private investigators around the world are racing to unlock the secret of Duqu, with early analysis suggesting that it was developed by sophisticated hackers to help lay the groundwork for attacks on critical infrastructure such as power plants, oil refineries and pipelines.
The equipment seized from Web Werks, a privately held company in Mumbai with about 200 employees, might hold valuable data to help investigators determine who built Duqu and how it can be used. But putting the pieces together is a long and difficult process, experts said.
"This one is challenging," said Marty Edwards, director of the U.S. Department of Homeland Security's Industrial Control Systems Cyber Emergency Response Team. "It's a very complex piece of software."
He declined to comment on the investigation by authorities in India, but said that his agency was working with counterparts in other countries to learn more about Duqu.
Two employees at Web Werks said officials from India's Department of Information Technology came to their office last week to take hard drives and other parts from a server.
They said they did not know how the malware got on to Web Werks' server. "We couldn't track down this customer," said one of the two employees, who did not want to be identified for fear of losing their jobs.
An official in India's Department of Information Technology who investigates cyber attacks also declined to discuss the matter. "I am not able to comment on any investigations," said Gulshan Rai, director of the Indian Computer Emergency Response Team, or CERT-In.
UNLOCKING THE SECRET
Stuxnet is malicious software designed to target widely used industrial control systems built by Germany's Siemens. It is believed to have crippled centrifuges that Iran uses to enrich uranium for what the United States and some European nations have charged is a covert nuclear weapons program.
Duqu appears to be more narrowly targeted than Stuxnet as researchers estimate the new trojan virus has infected at most dozens of machines so far. By comparison, Stuxnet spread much more quickly, popping up on thousands of computer systems.
Security firms including Dell Inc's SecureWorks, Intel Corp's McAfee, Kaspersky Lab and Symantec say they found Duqu victims in Europe, Iran, Sudan and the United States. They declined to provide their identities.
Duqu -- so named because it creates files with "DQ" in the prefix -- was designed to steal secrets from the computers it infects, researchers said, such as design documents from makers of highly sophisticated valves, motors, pipes and switches.
Experts suspect that information is being gathered for use in developing future cyber weapons that would target the control systems of critical infrastructure.
The hackers behind Duqu are unknown, but their sophistication suggests they are backed by a government, researchers say.
"A cyber saboteur should understand the engineering specifications of every component that could be targeted for destruction in an operation," said John Bumgarner, chief technology officer for the U.S. Cyber Consequences Unit.
That is exactly what the authors of Stuxnet did when they built that cyber weapon, said Bumgarner, who is writing a paper on the development of Stuxnet.
"They studied the technical details of gas centrifuges and figured out how they could be destroyed," he said.
Such cyber reconnaissance missions are examples of an increasingly common phenomenon known as "blended" attacks, where elite hackers infiltrate one target to facilitate access to another.
Hackers who infiltrated Nasdaq's computer systems last year installed malware that allowed them to spy on the directors of publicly held companies.
In March, hackers stole digital security keys from EMC Corp's RSA Security division that they later used to breach the networks of defense contractor Lockheed Martin Corp.
Researchers said they are still trying to figure out what the next phase of Duqu attacks might be.
"We are a little bit behind in the game," said Don Jackson, a director of the Dell SecureWorks Counter Threat Unit. "Knowing what these guys are doing, they are probably a step ahead."
(Reporting by Supantha Mukherjee in New York, Jim Finkle in Boston; Additional reporting by Henry Foy in Mumbai; Editing by Tiffany Wu)
Technology
Related Quotes and News
Company
Price
Related News
Tweet this
Link this
Share this
Digg this
Email
Reprints
We welcome comments that advance the story through relevant opinion, anecdotes, links and data. If you see a comment that you believe is irrelevant or inappropriate, you can flag it to our editors by using the report abuse links. Views expressed in the comments do not represent those of Reuters. For more information on our comment policy, see http://blogs.reuters.com/fulldisclosure/2010/09/27/toward-a-more-thoughtful-conversation-on-stories/
Comments (1)
Tom_Jerry wrote:
First Stuxnet then Duqu, is this new cold war era?
Oct 28, 2011 8:05pm EDT -- Report as abuse
See All Comments »
Add Your Comment
Social Stream (What's this?)
Edition:
U.S.
Africa
Arabic
Argentina
Brazil
Canada
China
France
Germany
India
Italy
Japan
Latin America
Mexico
Russia
Spain
United Kingdom
Back to top
Reuters.com
Business
Markets
World
Politics
Technology
Opinion
Money
Pictures
Videos
Site Index
Legal
Bankruptcy Law
California Legal
New York Legal
Securities Law
Support & Contact
Contact Us
Advertise With Us
Connect with Reuters
Twitter
Facebook
LinkedIn
RSS
Podcast
Newsletters
Mobile
About
Privacy Policy
Terms of Use
Our Flagship financial information platform incorporating Reuters Insider
An ultra-low latency infrastructure for electronic trading and data distribution
A connected approach to governance, risk and compliance
Our next generation legal research platform
Our global tax workstation
Thomsonreuters.com
About Thomson Reuters
Investor Relations
Careers
Contact Us
Thomson Reuters is the world's largest international multimedia news agency, providing investing news, world news, business news, technology news, headline news, small business news, news alerts, personal finance, stock market, and mutual funds information available on Reuters.com, video, mobile, and interactive television platforms. Thomson Reuters journalists are subject to an Editorial Handbook which requires fair presentation and disclosure of relevant interests.
NYSE and AMEX quotes delayed by at least 20 minutes. Nasdaq delayed by at least 15 minutes. For a complete list of exchanges and delays, please click here.