Anti-Malware Vendor Fight: Duqu vs. Stuxnet
November 03, 2011 | POSTED BY BRETT EDGAR IN MALWARE, SECURITY
It looks like the main anti-malware vendors are choosing sides and going head-to-head on the relationship between Duqu and Stuxnet. So far, the fight is Symantec and Kaspersky, who say Duqu is related to Stuxnet, vs. SecureWorks and Bitdefender, who say they are not related at all.
If you haven't heard, Duqu is a new piece of malware that has been found so far in Sudan and Iran and is spreading via an unknown method. It is similar to Stuxnet in that it installs a rootkit on infected machines and injects encrypted DLLs into the Windows kernel. As SecureWorks points out in this analysis
, none of this behavior is unique. It is dissimilar to Stuxnext in that it does not appear to be targeting SCADA PLCs, but is apparently a remote-access trojan that receives commands and exfiltrates data.
It seems to me that the anti-malware vendors are just trying to ride the coattails of the media coverage of Stuxnet. (Wait, isn't that what I'm doing here?)