<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Stuxnet on Omid Farhang</title><link>https://omid.dev/tags/stuxnet/</link><description>Recent content in Stuxnet on Omid Farhang</description><generator>Hugo -- 0.152.2</generator><language>en-US</language><copyright>2025 Omid Farhang | All rights reserved.</copyright><lastBuildDate>Wed, 27 Feb 2013 16:12:00 +0000</lastBuildDate><atom:link href="https://omid.dev/tags/stuxnet/index.xml" rel="self" type="application/rss+xml"/><item><title>Stuxnet Missing Link Found, Resolves Some Mysteries Around the Cyberweapon</title><link>https://omid.dev/2013/02/27/stuxnet-missing-link-found-resolves-some-mysteries-around-the-cyberweapon/</link><pubDate>Wed, 27 Feb 2013 16:12:00 +0000</pubDate><guid>https://omid.dev/2013/02/27/stuxnet-missing-link-found-resolves-some-mysteries-around-the-cyberweapon/</guid><description>&lt;p&gt;&lt;em&gt;Cross-posted from&lt;/em&gt; &lt;a href="http://www.wired.com/threatlevel/2013/02/new-stuxnet-variant-found/all/"&gt;&lt;em&gt;WIRED&lt;/em&gt;&lt;/a&gt;&lt;em&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://lh6.ggpht.com/-Ddf4V0bOokQ/US4pBrXxyuI/AAAAAAAAH3Y/0ibgWKrHlgY/s1600-h/Ahmadinejad-at-Natanz-in-2008%25255B5%25255D.jpg"&gt;&lt;img loading="lazy" src="http://lh4.ggpht.com/-MjRcWkbyBz4/US4pE-oaobI/AAAAAAAAH3g/hyVPMApvy1Q/Ahmadinejad-at-Natanz-in-2008_thumb%25255B2%25255D.jpg?imgmax=800" alt="Ahmadinejad-at-Natanz-in-2008" title="Ahmadinejad-at-Natanz-in-2008" /&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;As Iran met in Kazakhstan this week with members of the UN Security Council to discuss its nuclear program, researchers announced that a new variant of the sophisticated cyberweapon known as Stuxnet had been found, which predates other known versions of the malicious code that were reportedly unleashed by the U.S. and Israel several years ago in an attempt to sabotage Iran’s nuclear program.&lt;/p&gt;
&lt;p&gt;The new variant was designed for a different kind of attack against centrifuges used in Iran’s uranium enrichment program than later versions that were released, according to Symantec, the U.S-based computer security firm that &lt;a href="http://www.wired.com/threatlevel/2011/07/how-digital-detectives-deciphered-stuxnet/"&gt;reverse-engineered Stuxnet in 2010&lt;/a&gt; and also found the latest variant.&lt;/p&gt;</description></item><item><title>Narilam Worm manipulates databases in Iran</title><link>https://omid.dev/2012/11/24/narilam-worm-manipulates-databases-in-iran/</link><pubDate>Sat, 24 Nov 2012 12:37:00 +0000</pubDate><guid>https://omid.dev/2012/11/24/narilam-worm-manipulates-databases-in-iran/</guid><description>&lt;p&gt;&lt;a href="http://lh3.ggpht.com/-PWZn6EPgNBA/ULC4ZTERsPI/AAAAAAAAHmw/7b0Vu2LvK1s/s1600-h/narilam-iran%25255B5%25255D.png" target="_blank"&gt;&lt;img title="narilam-iran" border="0" alt="narilam-iran" align="right" src="http://lh4.ggpht.com/-Yh9UYyqtVKA/ULC4bob5OCI/AAAAAAAAHm4/240JKydkDLU/narilam-iran_thumb%25255B3%25255D.png?imgmax=800" width="244" height="153" /&gt;&lt;/a&gt;h-Online: Security firm Symantec has discovered a specialised worm called W32.Narilam that can compromise SQL databases. Symantec &lt;a href="http://www.symantec.com/connect/blogs/w32narilam-business-database-sabotage"&gt;reports&lt;/a&gt; that the malware “speaks” Persian and Arabic and appears to target mainly companies in Iran. Narilam is, therefore, reminiscent of &lt;a href="http://www.h-online.com/news/item/Stuxnet-worm-can-control-industrial-systems-1080751.html"&gt;Stuxnet&lt;/a&gt; and its &lt;a href="http://www.h-online.com/news/item/Kaspersky-says-Stuxnet-and-Flame-are-related-after-all-1615750.html"&gt;variants&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Narilam spreads via &lt;a href="http://www.h-online.com/news/item/Stuxnet-worm-was-planted-by-inside-man-1525260.html"&gt;USB flash drives&lt;/a&gt; and network shares. Once inside the system, the worm searches for SQL databases that are accessible via the &lt;a href="http://en.wikipedia.org/wiki/OLE_DB"&gt;Object Linking and Embedding Database&lt;/a&gt; (OLEDB) API. Rather than steal found target data for intelligence purposes, the worm proceeds to modify or delete the data and can, says Symantec, cause considerable damage. Stuxnet similarly served no intelligence purpose and was designed to sabotage its target – an uranium enrichment facility in Natanz, Iran.&lt;/p&gt;</description></item><item><title>On Stuxnet, Duqu and Flame</title><link>https://omid.dev/2012/06/03/on-stuxnet-duqu-and-flame/</link><pubDate>Sun, 03 Jun 2012 09:26:00 +0000</pubDate><guid>https://omid.dev/2012/06/03/on-stuxnet-duqu-and-flame/</guid><description>&lt;p&gt;F-Secure wrote:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;When we went digging through our archive for related samples of malware, we were surprised to find that we already had samples of Flame, dating back to 2010 and 2011, that we were unaware we possessed. They had come through automated reporting mechanisms, but had never been flagged by the system as something we should examine closely. Researchers at other antivirus firms have found evidence that they received samples of the malware even earlier than this, indicating that the malware was older than 2010.&lt;/em&gt;&lt;/p&gt;</description></item><item><title>FAQ: Flame, the &amp;quot;super spy&amp;quot;</title><link>https://omid.dev/2012/05/31/faq-flame-the-super-spy/</link><pubDate>Thu, 31 May 2012 12:51:00 +0000</pubDate><guid>https://omid.dev/2012/05/31/faq-flame-the-super-spy/</guid><description>&lt;p&gt;Copied from H-Online: &lt;a href="http://www.h-online.com/security/features/FAQ-Flame-the-super-spy-1587063.html" target="_blank"&gt;Source&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="http://lh3.ggpht.com/-QpyIQWVm1c0/T8diAgxhefI/AAAAAAAAGKM/9IpyOe4KSgU/s1600-h/FAQ_flame_kicker%25255B2%25255D.png"&gt;&lt;img title="FAQ_flame_kicker" border="0" alt="FAQ_flame_kicker" align="right" src="http://lh6.ggpht.com/-iSvtBbZ6D7E/T8diC1WvPAI/AAAAAAAAGKU/ztNk_M_At_I/FAQ_flame_kicker_thumb.png?imgmax=800" width="220" height="80" /&gt;&lt;/a&gt;The spyware worm Flame is being billed as a “deadly cyber weapon”, but a calmer analysis reveals it to be a tool by professionals for professionals that doesn&amp;rsquo;t actually have that many new features compared to, say, the widespread online-banking trojan Zeus.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What is Flame?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Flame is the code name for a spyware program that is built to be very modular and which is also known as Flamer and sKyWIper. Flame was just recently discovered, and it will be some time before all of its components are analyzed. Anti-virus software companies estimate that Flame has infected about 1,000 computers, mostly in the Middle East.&lt;/p&gt;</description></item><item><title>Flame worm – Iran claims to discover new Stuxnet-like malware</title><link>https://omid.dev/2012/05/28/flame-worm-iran-claims-to-discover-new-stuxnet-like-malware/</link><pubDate>Mon, 28 May 2012 14:57:00 +0000</pubDate><guid>https://omid.dev/2012/05/28/flame-worm-iran-claims-to-discover-new-stuxnet-like-malware/</guid><description>&lt;p&gt;Naked Security wrote:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://lh4.ggpht.com/-QohaM1XK7OA/T8OLUDmIspI/AAAAAAAAGHc/ZGu8EXRoFUQ/s1600-h/iran-flames-170%25255B2%25255D.jpg"&gt;&lt;img title="iran-flames-170" border="0" alt="iran-flames-170" align="right" src="http://lh3.ggpht.com/-H7i2lfAgAmg/T8OLWPeXIYI/AAAAAAAAGHk/Js_udYnFn9k/iran-flames-170_thumb.jpg?imgmax=800" width="170" height="128" /&gt;&lt;/a&gt;&lt;em&gt;The Iranian Computer Emergency Response Team (MAHER) claims to have discovered a new targeted malware attack attacking the country, which has been dubbed Flame (also known as Flamer or Skywiper).&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;In a&lt;/em&gt; &lt;a href="http://www.certcc.ir/index.php?name=news&amp;amp;file=article&amp;amp;sid=1894"&gt;&lt;em&gt;statement&lt;/em&gt;&lt;/a&gt;&lt;em&gt;, researchers say that they believe the malware is “a close relation” to Stuxnet, and claim that Flame is not detected by any of 43 anti-virus products it tested against, but that detection was issued to select Iranian organizations and companies at the beginning of May.&lt;/em&gt;&lt;/p&gt;</description></item><item><title>Duqu, Son of Stuxnet?</title><link>https://omid.dev/2011/10/20/duqu-son-of-stuxnet/</link><pubDate>Thu, 20 Oct 2011 22:23:00 +0000</pubDate><guid>https://omid.dev/2011/10/20/duqu-son-of-stuxnet/</guid><description>&lt;p&gt;&lt;a href="http://4.bp.blogspot.com/-W9csiY4HWJ8/TqCV1Mg85CI/AAAAAAAAEKE/E8-Ka-qvNoE/s1600/Screen-Shot-2011-10-18-at-12.26.12-PM.png"&gt;&lt;img loading="lazy" src="http://4.bp.blogspot.com/-W9csiY4HWJ8/TqCV1Mg85CI/AAAAAAAAEKE/E8-Ka-qvNoE/s400/Screen-Shot-2011-10-18-at-12.26.12-PM.png" alt="" /&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Schneier on Security:&lt;/strong&gt; A newly discovered piece of malware, Duqu, seems to be a precursor to the next Stuxnet-like worm and uses some of the same techniques as the original. &lt;a href="http://www.schneier.com/blog/archives/2011/10/new_malware_duq.html"&gt;Link to Source&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Symantec: W32.Duqu: The Precursor to the Next Stuxnet&lt;/strong&gt;&lt;br&gt;
Duqu is essentially the precursor to a future Stuxnet-like attack. The threat was written by the same authors (or those that have access to the Stuxnet source code) and appears to have been created since the last Stuxnet file was recovered. Duqu&amp;rsquo;s purpose is to gather intelligence data and assets from entities, such as industrial control system manufacturers, in order to more easily conduct a future attack against another third party. The attackers are looking for information such as design documents that could help them mount a future attack on an industrial control facility. &lt;a href="http://www.symantec.com/connect/w32_duqu_precursor_next_stuxnet"&gt;Read Full Article&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Stuxnet and WikiLeaks – What do they have in common?</title><link>https://omid.dev/2010/12/04/stuxnet-and-wikileaks-what-do-they-have-in-common/</link><pubDate>Sat, 04 Dec 2010 21:41:00 +0000</pubDate><guid>https://omid.dev/2010/12/04/stuxnet-and-wikileaks-what-do-they-have-in-common/</guid><description>&lt;p&gt;At first glance, two recent security stories, the Stuxnet attack on Iran&amp;rsquo;s nuclear industry and the WikiLeaks breach of US State Department communications, don&amp;rsquo;t seem to have much in common, but they do. They are united by a vector, a method of transmission and that vector is removable media.&lt;/p&gt;
&lt;p&gt;I am sure that the Iranians felt pretty secure with air-gapped systems, but like a spark from the burning house next door that finds its way into your shingles, the right USB found its way into the right PC and then suddenly all those uranium enrichment centrifuges running at 807-1210 hz started to act funny and fail in unexpected and reportedly fairly energetic ways (you can see some pics of failed centrifuges here &lt;a href="http://web.mit.edu/charliew/www/centrifuge.html"&gt;http://web.mit.edu/charliew/www/centrifuge.html&lt;/a&gt; and here &lt;a href="http://www.chem.purdue.edu/chemsafety/NewsAndStories/CentrifugeDamages.htm"&gt;http://www.chem.purdue.edu/chemsafety/NewsAndStories/CentrifugeDamages.htm&lt;/a&gt;).&lt;/p&gt;</description></item><item><title>Fake Stuxnet cleaner literally cleans up your computer</title><link>https://omid.dev/2010/10/15/fake-stuxnet-cleaner-literally-cleans-up-your-computer/</link><pubDate>Fri, 15 Oct 2010 15:12:00 +0000</pubDate><guid>https://omid.dev/2010/10/15/fake-stuxnet-cleaner-literally-cleans-up-your-computer/</guid><description>&lt;p&gt;W32.Stuxnet has been a subject of much discussion amongst security researchers and media, and we posted a series of blogs on the subject. As you may already be aware, Stuxnet is hot topic as the threat targets industrial control systems in order to take control of industrial facilities and systems, such as manufacturing assembly lines and even power plants.&lt;/p&gt;
&lt;p&gt;Because Stuxnet is such major news, the miscreants who like to spread malware are not wasting much time taking advantage of this for their malicious activities. In our investigations we have discovered that various forums are discussing a free Stuxnet removal tool but unfortunately the tool is actually a piece of malware. We successfully obtained a sample of this tool and our analysis supported our sense of danger: Bottom line is, &lt;strong&gt;do NOT run the tool&lt;/strong&gt;.&lt;/p&gt;</description></item><item><title>Stuxnet Questions and Answers</title><link>https://omid.dev/2010/10/06/stuxnet-questions-and-answers/</link><pubDate>Wed, 06 Oct 2010 22:32:00 +0000</pubDate><guid>https://omid.dev/2010/10/06/stuxnet-questions-and-answers/</guid><description>&lt;p&gt;&lt;strong&gt;Stuxnet&lt;/strong&gt; continues to be a hot topic. Here are answers to some of the questions we&amp;rsquo;ve received.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q:&lt;/strong&gt; What is Stuxnet?&lt;br&gt;
&lt;strong&gt;A:&lt;/strong&gt; It&amp;rsquo;s a Windows worm, spreading via USB sticks. Once inside an organization, it can also spread by copying itself to network shares if they have weak passwords.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q:&lt;/strong&gt; Can it spread via other USB devices?&lt;br&gt;
&lt;strong&gt;A:&lt;/strong&gt; Sure, it can spread anything that you can mount as a drive. Like a USB hard drive, mobile phone, picture frame and so on.&lt;/p&gt;</description></item><item><title>Stuxnet in the news</title><link>https://omid.dev/2010/09/30/stuxnet-in-the-news/</link><pubDate>Thu, 30 Sep 2010 22:34:00 +0000</pubDate><guid>https://omid.dev/2010/09/30/stuxnet-in-the-news/</guid><description>&lt;p&gt;The Stuxnet Trojan is very well covered in the media as more and more details about its sophisticated code become public. It abuses four previously unknown security vulnerabilities in Windows to enter the system and is specialized on attacking Siemens processing systems. An interesting information which didn’t get much attention yet comes from &lt;a href="http://www.h-online.com/security/news/item/Stuxnet-brings-more-new-tricks-to-cyberwar-1098810.html"&gt;heise Security&lt;/a&gt;: The nuclear plant in Busheer isn’t really the target of the worm as rumours say, as the attacked systems aren’t approved for usage in nuclear plants.&lt;/p&gt;</description></item></channel></rss>