Son of Stuxnet Found in the Wild on Systems in Europe
wired.com
wired.com
Current binary to C decompilers are not sufficient to reproduce and modify moderately complex software. They just make analysis easier, because it's more like reading pseudocode.
How do you run that backwards to get data out? Surely not thumb drives again?
I would assume that master copy of the Duqu takes over a computer then installs a recon'ing version on the USB stick that travels to the targeted facilities.
Of course this assumes Duqu's purpose/target/method are the same as Stuxnet. It could also be true that the attackers already know the info about the facility. All this strain of the virus is looking for is someone who works there.
I dunno...the ambiguity (in the article) is so high that the number of plausible scenarios is up there too.
But they did point out that it was actually sending stuff back at the top of the article, so I'm equally confused!