Firstpost
  • Home
  • Video Shows
    Vantage Firstpost America Firstpost Africa First Sports
  • World
    US News
  • Explainers
  • News
    India Opinion Cricket Tech Entertainment Sports Health Photostories
  • Asia Cup 2025
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
Trending:
  • Nepal protests
  • Nepal Protests Live
  • Vice-presidential elections
  • iPhone 17
  • IND vs PAK cricket
  • Israel-Hamas war
fp-logo
Duqu attackers wiped Linux C&C servers
Whatsapp Facebook Twitter
Whatsapp Facebook Twitter
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
  • Home
  • Tech
  • News & Analysis
  • Duqu attackers wiped Linux C&C servers

Duqu attackers wiped Linux C&C servers

Naina Khedekar • December 1, 2011, 11:32:58 IST
Whatsapp Facebook Twitter

The Duqu malware has been creating havoc in the industrial sector across the world. The Indian officials had shut down …

Advertisement
Subscribe Join Us
Add as a preferred source on Google
On
Google
Prefer
Firstpost
Duqu attackers wiped Linux C&C servers

The Duqu malware has been creating havoc in the industrial sector across the world. The Indian officials had shut down a server linked to Duqu in Mumbai, which was later taken under the hood for further investigation. The malicious was also fixed temporarily by Microsoft. The researchers from Kaspersky Lab who have been studying the Command and Control infrastructure by Duqu, have now revealed in  a report that these attackers have made some critical mistakes with an attempt to clear evidence.

STORY CONTINUES BELOW THIS AD

Kaspersky report

Kaspersky report (Image Credit: Securelist)

The researchers showed that DuQu C&C servers were operated since November 2009. Most of the hacked machines were running on CentOS Linux. The attackers updated OpenSSH 4.3 to version 5 after gaining control each time. The report says, “Unfortunately, the most interesting server, the C&C proxy in India, was cleaned only hours before the hosting company agreed to make an image. If the image had been made earlier, it’s possible that now we’d know a lot more about the inner workings of the network.”

More from News & Analysis
What is the US HIRE Bill and why is India’s $250-billion IT sector worried? What is the US HIRE Bill and why is India’s $250-billion IT sector worried? Is the internet dead? What's this theory that OpenAI's Sam Altman says might be true? Is the internet dead? What's this theory that OpenAI's Sam Altman says might be true?

According to the report, attackers took up a global cleanup operation on the various several Linux servers, which were used to control systems infected with DuQu on October 20. This was attempted on systems running on CentOS 5.x, just two days after the Duqu was compared publicly with Stuxnet. It is speculated that the operators were trying to cover their tracks. This was possibly done in a hurry, which led to the attackers making a critical mistake, as servers in Vietnam and Germany have partial logs of the hackers’ SSH.

The sshd.log files displayed that the attackers had logged into a Vietnam-based machine in July and in October, while they logged into a Germany-based system in as early as November 23, 2009. The servers were proxies which were designed to cover up attackers’ location. The real Duqu mothership C&C server and of course the identity of attackers isn’t disclosed yet.

Tags
cyber attacks Kaspersky Lab software Cyber crime Duqu Virus Stuxnet Trojan Virus Symantec Corp. Web Werks Malacious Duqu Stuxnet Iran U.S. Department of Homeland Security Kaspersky Lab report
End of Article
Written by Naina Khedekar
Email

Armed with a Bachelor of Electronics Engineering degree, it is writing where Naina finds her calling. She has got her finger on the pulse of what's new and trending in the world of technology, right from gadgets to innovations. When she isn't hammering away on her keyboard, she is busy looking for figurines to add to her growing collection of Kinder toys. It doesn't get more diverse than that. see more

Latest News
Find us on YouTube
Subscribe
End of Article

Top Stories

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Who is CP Radhakrishnan, India's next vice-president?

Who is CP Radhakrishnan, India's next vice-president?

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Who is CP Radhakrishnan, India's next vice-president?

Who is CP Radhakrishnan, India's next vice-president?

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Top Shows

Vantage Firstpost America Firstpost Africa First Sports
Latest News About Firstpost
Most Searched Categories
  • Web Stories
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Tech/Auto
  • Entertainment
  • IPL 2025
NETWORK18 SITES
  • News18
  • Money Control
  • CNBC TV18
  • Forbes India
  • Advertise with us
  • Sitemap
Firstpost Logo

is on YouTube

Subscribe Now

Copyright @ 2024. Firstpost - All Rights Reserved

About Us Contact Us Privacy Policy Cookie Policy Terms Of Use
Home Video Shorts Live TV