Who Wrote the Nefarious Stuxnet Worm? And Why?

Who Wrote the Nefarious Stuxnet Worm? And Why?

Imagine a nefarious computer virus, one some industry experts say may bethe most sophisticated piece of malware ever written. Imagine this worm,loaded onto a Siemens Programmable Logic Controller (PLC),creating two hexadecimal words as its output: DEAD F007. Now imaginethis piece of malware, Stuxnet — or somethinglike it — coming to an industrial plant near you.

[login]Let’s start by dispelling one myth that seems to be growing up aroundthis piece of PLC-controlling software: PLCs are not super-secretdevices, but are standard bits of industrial control equipment that cancost as little as $200 (and, for really complicated ones, manythousands), and are available from industrial supply houses all over theworld without any kind of security check. The software used to programPLCs is no more secret than the devices themselves. WinCC,the compromised program, may not be known to many programmers orsysadmins who work in offices, but it is a familiar tool for industrialplant people in many different fields.

Siemens, based in Germany is one of the biggest of multinational bigdogs in the PLC field. They sell into the U.S., China, Brazil, India,and almost anywhere else there’s any industry at all. Want to countcereal boxes on an assembly line and measure out the right amount ofcereal for each one? You can program a Siemens PLC for that application,no problem. Want to spin your Uranium-enrichment centrifuges at just theright speed? Ditto. Or run track-mounted speed detectors and switch gearfor your high-speed rail system or the moisture control on your Yankee dryer? Noproblem. If there isn’t a PLC app for that already, writing one is nobig deal.

An early article about the Stuxnet infection in Iran claimed that itinfected “millions” of industrial control computers there. This isunlikely. Indeed, it’s unlikely that Iran has millions of industrialcontrol computers, period. And Stuxnet is not — at least in formsdiscovered so far — an Internet-spread problem, but one that typicallyinfects a computer network when someone plugs a USB stick containing theworm into a computer on that network.

Another article,on Forbes.com, postulated that the Stuxnet worm’s purpose was to disablesatellites run by the Indian Space Research Organization, which wouldmean more business and prestige for China’s AsiaSat.

And maybe some Siemens PLCs are not supposed to be going to Iran, afterall. A New York Times storypublished on Sept. 29 said, “…last year officials in Dubai seized alarge shipment of those controllers — known as the Simatic S-7 — afterWestern intelligence agencies warned that the shipment was bound forIran and would likely be used in its nuclear program.”

That same story mentions the Biblical-sounding connection of one of theworm’s file names to the Book of Esther,”a clear warning in a mounting technological and psychological battle asIsrael and its allies try to breach Tehran’s most heavily guardedproject.” But it also says, “Others doubt the Israelis were involved andsay the word could have been inserted as deliberate misinformation, toimplicate Israel.”

And then there’s that DEAD F007 “leetspeak” PLC output. Eric Loyd,President of Bitnetix, says thatno matter how juvenile DEAD F007 sounds, “Stuxnet is far from akid-hacker attack.” Indeed, Loyd is one of many IT experts who believesStuxnet may be the most sophisticated piece of malware ever written,with its use of four seperate Windows zero-day attacks, not one but twogenuine security certificates (now revoked), and it’s ability to not onlymonitor but modify instructions for the targeted Siemens PLCs.

While PLCs may be a mystery to many — even most — programmers andsyadmins, they are not complicated, nor do they take advanced degrees tofigure out. In most of the industrial world, they are the responsibilityof guys who wear their names on their shirts. Indeed, the whole point ofSCADA is that it makesplant processes easy to visualize and control.

So far there is no concrete evidence that Stuxnet-infected computers orPLCs have affected Iran’s nuclear fuel enrichment program or delayed thestartup of the country’s one nuclear reactor. But there are suspiciouscoincidences that make it seems like Stuxnet might have donesomething to Iran’s nuclear efforts, depending on whichcontradictory reports coming out of Iran you want to believe.

On one hand Iranian government sources say Stuxnet has not causedproblems or delays to anything nuclear, and on the other they claim they have arrested “NuclearCyberspace Spies” and is “fully aware of the activities of ‘enemies’spy services.'”

Stuxnet may not be the biggest problem

Whether Stuxnet is the work of Chinese or Israeli governmentcyberwarriors or a computer science student’s prank that got out ofhand, there are cures for it, and Microsoft is closing the four Windowszero-day vulnerabilities that allows the worm to do its mischief and topropagate laterally within a government or corporate computer network.And with the right malware protection, a Stuxnet infection can bedetected immediately, says Kurt Bertone, Vice President of StrategicAlliances for FidelitySecurity Systems, who says his company’s XPS cyber defense productshas no trouble dealing with Stuxnet.

Other virus detection and malware control companies also now have ahandle on Stuxnet, including Siemens, which offers completeStuxnet detection and removal instructions.

But the problem now, Bertone warns, is not so much Stuxnet but otherpieces of malware that are out there but may not have been discovered.He and Eric Loyd both worry that there may be some “Son of Stuxnet” wormout there, spread manually, like Stuxnet, or by some other vector, thatwill one day cause dangereous problems at nuclear plants, oil refineriesor chemical plants or….

…there are millions of critical points in our modern industrialinfrastructure that use PLCs and other computer-based controls, some ofwhich are carefully secured against malware infections — and some ofwhich are not secure at all but have not yet been attacked.

devx-admin

devx-admin

Share the Post:
Razer Discount

Unbelievable Razer Blade 17 Discount

On September 24, 2023, it was reported that Razer, a popular brand in the premium gaming laptop industry, is offering an exceptional deal on their

Innovation Ignition

New Fintech Innovation Ignites Change

The fintech sector continues to attract substantial interest, as demonstrated by a dedicated fintech stage at a recent event featuring panel discussions and informal conversations

Import Easing

Easing Import Rules for Big Tech

India has chosen to ease its proposed restrictions on imports of laptops, tablets, and other IT hardware, allowing manufacturers like Apple Inc., HP Inc., and

Anthropic Investment

Amazon’s Bold Anthropic Investment

On Monday, Amazon announced its plan to invest up to $4 billion in the AI firm Anthropic, acquiring a minority stake in the process. This

Razer Discount

Unbelievable Razer Blade 17 Discount

On September 24, 2023, it was reported that Razer, a popular brand in the premium gaming laptop industry, is offering an exceptional deal on their Razer Blade 17 model. Typically

Innovation Ignition

New Fintech Innovation Ignites Change

The fintech sector continues to attract substantial interest, as demonstrated by a dedicated fintech stage at a recent event featuring panel discussions and informal conversations with industry professionals. The gathering,

Import Easing

Easing Import Rules for Big Tech

India has chosen to ease its proposed restrictions on imports of laptops, tablets, and other IT hardware, allowing manufacturers like Apple Inc., HP Inc., and Dell Technologies Inc. more time

Semiconductor Stock Plummet

Dramatic Downturn in Semiconductor Stocks Looms

Recent events show that the S&P Semiconductors Select Industry Index seems to be experiencing a downturn, which could result in a decline in semiconductor stocks. Known as a key indicator

Anthropic Investment

Amazon’s Bold Anthropic Investment

On Monday, Amazon announced its plan to invest up to $4 billion in the AI firm Anthropic, acquiring a minority stake in the process. This decision demonstrates Amazon’s commitment to

AI Experts Get Hired

Tech Industry Rehiring Wave: AI Experts Wanted

A few months ago, Big Tech companies were downsizing their workforce, but currently, many are considering rehiring some of these employees, especially in popular fields such as artificial intelligence. The

Lagos Migration

Middle-Class Migration: Undermining Democracy?

As the middle class in Lagos, Nigeria, increasingly migrates to private communities, a PhD scholar from a leading technology institute has been investigating the impact of this development on democratic

AI Software Development

ChatGPT is Now Making Video Games

Pietro Schirano’s foray into using ChatGPT, an AI tool for programming, has opened up new vistas in game and software development. As design lead at business finance firm Brex, Schirano

Llama Codebot

Developers! Here’s Your Chatbot

Meta Platforms has recently unveiled Code Llama, a free chatbot designed to aid developers in crafting coding scripts. This large language model (LLM), developed using Meta’s Llama 2 model, serves

Tech Layoffs

Unraveling the Tech Sector’s Historic Job Losses

Throughout 2023, the tech sector has experienced a record-breaking number of job losses, impacting tens of thousands of workers across various companies, including well-established corporations and emerging startups in areas

Chinese 5G Limitation

Germany Considers Limiting Chinese 5G Tech

A recent report has put forth the possibility that Germany’s Federal Ministry of the Interior and Community may consider limiting the use of Chinese 5G technology by local network providers

Modern Warfare

The Barak Tank is Transforming Modern Warfare

The Barak tank is a groundbreaking addition to the Israeli Defense Forces’ arsenal, significantly enhancing their combat capabilities. This AI-powered military vehicle is expected to transform the way modern warfare

AI Cheating Growth

AI Plagiarism Challenges Shake Academic Integrity

As generative AI technologies like ChatGPT become increasingly prevalent among students and raise concerns about widespread cheating, prominent universities have halted their use of AI detection software, such as Turnitin’s

US Commitment

US Approves Sustainable Battery Research

The US Department of Energy has revealed a $325 million commitment in the research of innovative battery types, designed to enable solar and wind power as continuous, 24-hour energy sources.

Netanyahu Musk AI

Netanyahu and Musk Discuss AI Future

On September 22, 2023, Israeli Prime Minister Benjamin Netanyahu met with entrepreneur Elon Musk in San Francisco prior to attending the United Nations. In a live-streamed discussion, Netanyahu lauded Musk

Urban Gardening

Creating Thriving Cities Through Urban Gardening

The rising popularity of urban gardening is receiving increased recognition for its numerous advantages, as demonstrated in a recent study featured in the Environmental Research Letters journal. Carried out by

What You Need to Know About Cloud Security Strategies

What You Need to Know About Cloud Security Strategies

Today, many businesses are adopting cloud computing services. As a result, it’s important to recognize that security measures for data in the cloud are different from those in traditional on-premises

Romanian Energy Security

Eastern Europe is Achieving Energy Security

Canada and Romania have solidified their commitment to energy security and independence from Russian energy exports by signing a $3-billion export development agreement. The deal is centered on constructing two

Seamless Integration

Unlocking Seamless Smart Home Integration

The vision of an intelligently organized and interconnected smart home that conserves time, energy, and resources has long been desired by many homeowners. However, this aspiration has often been hindered

New Algorithm

MicroAlgo’s Groundbreaking Algorithm

MicroAlgo Inc. has revealed the creation of a knowledge-augmented backtracking search algorithm, developed through extensive research in evolutionary computational techniques. The algorithm is designed to boost problem-solving effectiveness, precision, and

Poland Energy Future

Westinghouse Builds Polish Power Plant

Westinghouse Electric Company and Bechtel have come together to establish a formal partnership in order to design and construct Poland’s inaugural nuclear power plant at the Lubiatowo-Kopalino site in Pomerania.

EV Labor Market

EV Industry Hurting For Skilled Labor

The United Auto Workers strike has highlighted the anticipated change towards a future dominated by electric vehicles (EVs), a shift which numerous people think will result in job losses. However,