Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

October 1st, 2010, 09:15 GMT · By

New Hint Points to Israel Connection in Stuxnet Case

SHARE:

Adjust text size:


Stuxnet contains referece to Habib Elghanian's execution
Enlarge picture
Security researchers revealed that there is at least one reference in the code of the notorious Stuxnet worm that would suggest a connection with Israel.

The Stuxnet malware, which has been built for industrial espionage and/or sabotage, is already viewed as the most sophisticated malware ever created.

The worm was discovered in July and is capable of stealing information from Siemens SCADA systems, which are used in many of the world's power plans, oil and gas refineries or factories.

It is also capable of writing hidden code to the PLCs (programmable logic controllers) used by SCADA systems, which means it can potentiall sabotage critical installations.

Due to its never-before-seen sophistication, the worm is most certainly the work of a specialized team of programmers and not amateur hackers.

Since Iran was one of the most affected countries, some people have speculated that Stuxnet is the creation of a nation-state, with US and Israel as likely candidates, that targeted the country's Bushehr nuclear power plant.

Symantec's malware researcher Liam O Murchu, who was actively involved in researching Stuxnet, held a presentation about the threat at the VB2010 conference in Vancouver yesterday.

O Murchu disclosed that there is a "05091979" marker in the code, which might reference the date of May 9, 1979, when Habib Elghanian, the president of the Tehran Jewish Society, was executed by the newly installed Islamic regime in Iran.

The event was strongly criticized by the Western countries at the time and his execution marked the beginning of the exodus of the Iranian Jewish community.

While this might seem to suggest that Israel could be involved, or at least that Iran was the primary target of the attack, the researcher advises caution in drawing such conclusions.

He points out that the reference might just as well have been placed there by the code writers to mislead or to intentionally implicate Israel.

There was also a separate Stuxnet-related presentation at the conference in which researchers from Kaspersky, Symantec and Microsoft, jointly discussed the four zero-day Windows vulnerabilities exploited by the worm.

Update: Corrected the referenced year from 1975 to 1979.

TELL US WHAT YOU THINK:

1,409 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


After Hitting Iran Hard Stuxnet Attacks Kazakhstan and Russia

Stuxnet Uses Binary Planting to Spread

Stuxnet Worm Features P2P Update Component

Stuxnet Industrial Espionage Malware Exploits Not One but Four Windows Zero-Day Vulnerabilities

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM