Blog

Blog: Blog

W32.Duqu: The Precursor to the Next Stuxnet

Uncategorized

According to Symantec, Duqu is the precursor to another Stuxnet type attack. However Duqu does not contain industrial like controls. It is primarily a remote access Trojan.

Quote

On October 14, 2011, a research lab with strong international connections alerted us to a sample that appeared to be very similar to Stuxnet. They named the threat “Duqu” [dyü-kyü] because it creates files with the file name prefix “~DQ”. The research lab provided us with samples recovered from computer systems located in Europe, as well as a detailed report with their initial findings, including analysis comparing the threat to Stuxnet, which we were able to confirm. Parts of Duqu are nearly identical to Stuxnet, but with a completely different purpose.

Complete Symantec article: http://www.symantec.com/connect/w32_duqu_precursor_next_stuxnet

More on Duqu from Wired.com by Kim Zetter: http://www.wired.com/threatlevel/2011/10/son-of-stuxnet-in-the-wild/

Quote

A little more than one year after the infrastructure-destroying Stuxnet worm was discovered on computer systems in Iran, a new piece of malware using some of the same techniques has been found infecting systems in Europe, according to researchers at security firm Symantec.The new malware, dubbed “Duqu” [dü-kyü], contains parts that are nearly identical to Stuxnet and appears to have been written by the same authors behind Stuxnet, or at least by someone who had direct access to the Stuxnet source code, says Liam O Murchu.

© 2026 SkyValley Digital. All Rights Reserved.