Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Stuxnet Malware Mystery Deepens: Another Hint Of Israeli Origins

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Archives » General Discussion (1/22-2007 thru 12/14/2010) Donate to DU
 
Poll_Blind Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Oct-01-10 01:22 PM
Original message
Stuxnet Malware Mystery Deepens: Another Hint Of Israeli Origins
From Haaretz:

The mystery continues to deepen over the origin of one of the world's most damaging computer viruses -- Stuxnet -- which some experts believe is targeted at Iran's nuclear power plants, slowing that country's quest for a nuclear weapon.

On Tuesday, a German computer specialist offered a hint that Israel may be behind the sophisticated malware, by demonstrating that a file inside the code uses the word "Myrtus" -- which could be a reference to the Book of Esther, the Old Testament story about how the Jews prevented a nefarious plot by the Persians, according to the New York Times.

The next day, a trio of security researchers offered another clue at a conference in Vancouver, describing how Stuxnet includes references to the 1979 execution of the leader of Iran's Jewish community at the time. Specifically, the researchers from Symantec -- Nicolas Falliere, Liam O Murchu and Eric Chen -- showed that the code includes a marker with the numbers "19790509" which, if prompted, stops the code from infecting a targeted computer.


While Stuxnet is, without a doubt...beyond the shadow of a doubt...both the most dangerous piece of malware ever (it specifically targets control systems for industrial machines) and the most expensive to design...and while there are just a few countries on Earth right now that could possibly, or would possibly, spend the millions in R&D and commit the criminal acts to breach secret signing keys from two major companies....and all the other incredibly exotic criminal acts...including being in possession of no less than 4 unheard-of Microsoft Windows exploits which were used to propagate this thing from PC to PC until it could reach it's real target...

All of those things and half a dozen more, admittedly, point fingers at Israel. Israel has acquired, encouraged a certain type of reputation over the decades for being extremely vengeful in retaliation and not caring about collateral damage. Everything...all of it...has so many things "typical" of an Israeli operation...

But I am still not sold Israel had anything to do with it. And here's why:

It starts with a little side-note about brilliant people, who are usually the ones who can do forensics on these sorts of malware: They have exceptional pattern-finding abilities. Pattern finding abilities are an essential element of intelligence. Think about every IQ test you ever took. Remember all those "Which of these comes next in the sequence?" questions. That's all about how well you can find the pattern given precious little information.

But the problem is, there is a fine line between being blessed with an uncommonly-keen pattern matching ability and having a brain which pattern matches too much. Paranoid schizophrenics are a great example of brains which play this particular game too well. For some people, like the famous John Forbes Nash, Jr. (on whom the movie "A Beautiful Mind" is based) the brilliance dances just on the line between sanity and madness.

And because the level of expertise and access to information and money and hardware and flat-out diabolical brilliance was so great in the creation of this malware, and because the creators knew this thing would be analyzed more than any piece of malware ever created...and what type of minds would be analyzing it, at the lowest level...The clues in the malware (more of which I'm sure will come out over weeks and months to come) were intentionally left there. And I am convinced the clues were no less well-tailored than any other part of this thing.

IMO, there is a high probability that an entire basket of extremely obscure "clues" were enmeshed with the malware, all designed to be seized upon by minds who feed off of, thrive off of mysteries like this...and to lead them to a conclusion which they will have felt they have unraveled themselves but which was intentionally planted for their finding.

That would be on par with the rest of the design of this thing, which is a piece of software so uniquely devastating that the security community patted themselves on the back years ago when they cogitated that such a thing as this could hypothetically exist in the first place.

So, if a week from now you see a news report that if looking at the binary code of this malware in base-1948 a Star of David resolves itself out of ones and zeros, or that the malware contains an encrypted jpg of Alan Dershowitz's moustache- taken during a 1985 trip...to ISRAEL...just remember those things did not wind up in there by accident any more than the "myrtus/guavva" pair or the "19790509" marker.

Could they be signs of bravado from Israeli computer warfare specialists? Absolutely. But there are other explanations and only time will tell, if ever.

This infection is world-wide and PC's and industrial systems all over the world are infected. Every government which runs Siemens PLC's in their infrastructure (which is a LOT) are under the gun here, not just Iran. Whomever created this does not want the heat and it would make sense to try as hard as possible to transfer the blame to somebody else for its creation.

PB
Printer Friendly | Permalink |  | Top
Me. Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Oct-01-10 03:07 PM
Response to Original message
1. I Read That And Couldn't Male Up My Mind
If it was the bravado you mention, someone was trying to implicate the Israelis or the Israelis did it to give themselves plausible deniability on the order of "why would we leave such an obvious clue?".
Printer Friendly | Permalink |  | Top
 
Poll_Blind Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Oct-01-10 05:04 PM
Response to Reply #1
3. Whomever created the worm might have also realized that in the next 6 months the...
...question of who created the original Stuxnet will be essentially moot as security companies scramble to deal with copycat malware using modified Stuxnet worms to do their bidding.

PB
Printer Friendly | Permalink |  | Top
 
DavidDvorkin Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Oct-01-10 03:28 PM
Response to Original message
2. Moreover, the name, Stuxnet, contains an e, and so does the word Israel
I think that proves it conclusively.

Good grief.
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Tue May 07th 2024, 02:39 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Archives » General Discussion (1/22-2007 thru 12/14/2010) Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC