Kaspersky: Duqu Trojan uses 'unknown programming language'
zdnet.com
zdnet.com
http://www.grammatech.com/research/products/CodeSurferx86.ht...
If it has access to source code, it can instrument the build process, and obtain disassembly that is high quality enough to support rewriting. Using it's scheme API you can modify the CFG of each procedure directly, serialize the rewritten parts out as nasm, and even relink with the object files you don't have source for.
It works with any build system, and supports gcc / as / ld and cl / link.
So it may not have actually been written using a custom pl.
http://philosecurity.org/2009/01/12/interview-with-an-adware...
Looks like a cool product.
At any rate, I don't think that if it was Scheme that the goal was to obfuscate that it was written in Scheme.
Hiding the source language makes identifying the origin of the malware difficult. There are obvious reasons to do that.
How so? Knowing that it was written using VC would hardly help identifying the origin.
That's not to say that you're wrong about the tool used, but I don't believe the goal was to cover their tracks, but some kind of optimization. Viruses often face space constraints.
I am confident that within a week there will be 3 front page posts on HN along the lines of 'Why I use Duqu and you should too'.
> Duqu and Stuxnet components date to 2007
We have online revolutionaries anarchists and REAL nation-wide revolutions, started on online networks (talking about Arabic Spring here); we got FBI agents, looking through IP addresses on IRC networks to catch a small group of bragging attackers; we got invisible army of Chinese hackers that noone knows who they are, only that they are really good; some unknown entity making amazingly well done and thought out trojan like stuxnet and now duqu, that seems to be right from pages of some hyperbolic comic book; and, last but not the least, the Russian mafia lords employing Zeus trojans and whatnot to make botnets that mine bitcoin, purely digital currency.
It's an amazing world we live in. Can't wait what the future will bring.
And yet, I can't help myself but watch in fascination as all this happens. Maybe it's because this time, the war is fought with means and tools I understand (if only a little)? Maybe.
Maybe it has something to do with the morbid fascination people have with anything destructive - the World War II books and movies are still sold like cakes, while noone actually wants to repeat the world war.
And for me, it's definitely not about the destruction. I just think it's awesome to realize just what humans are capable of. Now, humans are also capable of some ridiculously destructive things. But the problem with @adriand's point of view is that it's as if there's something to be lost from all of Man's destruction. When really, what significance does Earth have in the Universe anyway?
Also, it is possible that Earth is significant to the universe because it's the only place where intelligent life has arisen. I don't expect that this is actually the case, but so far we have no evidence to the contrary, and if it were true it would be tragic if we wiped ourselves out by playing with virii and nuclear technology.
What if it had never happened? Now we now there were previous attempts at industry, like steam engines and chemistry, but there was always a war, a drought or some other disaster that destroyed the framework where said developments were made, and sometimes even killed the people making them (Archimedes for example).
What if the universe is just like that? what if we're the most advanced species and all the aliens out there are either animals or still haven't even figured out how to build clocks or engines?
If that's the case then all the knowledge that ever existed would die with us.
I find online wars to be much more favorable than actual bloodshed. Even an occasional meltdown would be much less disastrous than real life conflict.
Considering some scientists were fearful that Stuxnet would cause a mini Chernobyl-like disaster, we can safety say that's not an unlikely scenario.
http://articles.nydailynews.com/2011-01-17/news/27087828_1_r...
"High tech meets low life".
http://www.securelist.com/en/blog/667/The_Mystery_of_the_Duq...
So something like compiled javascript sans GC really. Or maybe like precompiled python.
Doesn't seem very obfuscated either imho - there's a bunch of static data copied in a series of moves. If someone really wanted to obfuscate those, this looks like a fairly low hanging fruit: grab a list of 5+ mov-s of constants and change them into xor+copy of a memory range to confuse pointer detection.
Can you see any more characteristics in that fragment?
-Everything is wrapped into objects
-Function table is placed directly into the class instance and can be
modified after construction
-There is no distinction between utility classes (linked lists, hashes) and
user-written code
-Objects communicate using method calls, deferred execution queues and
event-driven callbacks[1] http://www.planetpdf.com/codecuts/pdfs/ooc.pdf [2] http://www.jirka.org/gob.html
I would just be very surprised if this is anything other than some convention developed on top of C.
http://www.securelist.com/en/blog/667/The_Mystery_of_the_Duq...
> The code your referring to .. the unknown c++ looks like the older IBM compilers found in OS400 SYS38 and the oldest sys36.
> The C++ code was used to write the tcp/ip stack for the operating system and all of the communications. The protocols used were the following x.21(async) all modes, Sync SDLC, x.25 Vbiss5 10 15 and 25. CICS. RSR232. This was a very small and powerful communications framework. The IBM system 36 had only 300MB hard drive and one megabyte of memory,the operating system came on diskettes.
> This would be very useful in this virus. It can track and monitor all types of communications. It can connect to everything and anything.
When I read these kind of sentences I always think of Plan9 first
More unusual (to me) is that there are two separate comments suggesting it may be RPG (an OS400/iSeries language), which is very unlikely due to it not being an OOP language therefore not having constructor/destructor functionality, and otherwise a very high level language.
I'd guess some high level assembly, though this suggestion does look interesting.
http://www.securelist.com/en/blog/667/The_Mystery_of_the_Duq...
I think it makes a lot of sense to write a custom programming language/compiler because virus scanners tend to use fingerprints to recognize dangerous pieces of code. So you want a compiler that deliberately obfuscates the code it writes and also outputs instructions in such a way that it avoids triggering known virus scanner fingerprints.
Instead of trying to compile code examples in every candidate PL, they should:
1. Crawl x86 binaries from the Internet / download sites / code archives.
2. Write M/R job, which will disassemble and look for patterns they discovered.
3. Once patterns found - investigate the source of binary (i.e. who uploaded it to download site, maybe it was on university FTP server or maybe it's part of commercial driver released by company XYZ).
Especially because of the name mangling i was thinking of Vala [0]. However, Vala relies on GObject and does probably not work on Windows. Anyways, I guess it's an OO language compiled to C in an intermediate step. This would explain (2).
We have what is effectively an alien virus, given how advanced it was, its construction and spawing of duqu and being written in an unknown language.
This is serious awesome cyberpunk stuff - but scary as hell at the same time.
With the revelation of Stuxnet and Duqu, NOBODY should think anything they do/say online is safe.
Of course, it might be that they didn't create a new language "just to write this", but because they're planning/already written other things in it.
My bet is that it's just C with a hand-rolled OO framework.
It is quite amusing to see how many old ideas from the dawn of computing have been reinvented multiple times over the years.
It's not particularly hard to write a simple programming language. Worms are very specialized pieces of code. It doesn't seem that crazy that someone would create a language tailored for worm development.
The sheer complexity is off the charts. Stuxnet's sophistication and complexity is an cybernetic equivalent of Manhattan project. E.g.: As a domain expert on industrial automation of this kind Langners states that whoever created Stuxnet _had to have a testing facility_. How many hackers do you know who build uranium enrichment centrifuges to test their cyber attack tools?
Yeah thought so.
Edit: TL;DR: There are two pieces of evidence. No.1: Motive, No.2: Sophistication and complexity.
The authors learnt from the Stuxnet experience and I wouldn't be surprised if they are not testing their own worm using black-box reverse engineering tools to figure out what the research guys will work out when they eventually find it in the wild.
This has worked so well that Kaspersky think that the authors actually invented a new language, when it is likely still just C++, some machine generated code, some obfuscator tools (game makers have been using them for years to stop crackers) and likely manually changing the outputted assembler.
Don't they mention that these components were floating around in 2007?
They also completely rule out C++, C etc. when what they should be ruling out is C++, C compiled with a standard VS compiler (or an easily recognizable compiler). It is silly to completely rule out C++ and C just because they don't immediately recognize the output and because it doesn't reference anything else
"Duqu was first detected in September 2011, but Kaspersky Lab believes it has seen the first pieces of Duqu-related malware dating back to August 2007"
http://en.wikipedia.org/wiki/Not_invented_here#In_computing
It also seems to me that a new language for this exact purpose is unlikely, however, it could very well be a proprietary or otherwise unknown language that may have been built for another purpose (internal company, domain-specific development, etc) and not often seen in this context.
Writing a detector for a virus with infinite code representations would be difficult.
This is referred to as Stuxnet 2. And the original was "proven" to have been made to attack Iranian nuclear labs, and what not. Conclusion being that it was made by some government agency. I suppose foil hat theory would point fingers at CIA/NSA type people.
Assuming the above is correct, or correct enough, its it not surprising to see what might be a new language for this virus, if it has a nation state's resources behind it? If that is the case, what chance is there that any one will be able to crack this mystery?
I haven't heard any similar speculation about Duqu.
The amount of effort that went into Stuxnet is truly massive. It'd be no surprise if a custom framework or even a domain-specific language were written to support it.
* Usually I cringe at just hearing the phrase cyber warfare and at the ridiculous way in which it is used by media and the government. But looking at what Stuxnet accomplished (physically damaging or disabling critical components of the Iranian nuclear enrichment program), the term applies completely.
If I were to guess, from the description they gave, it sounds like someone compiled erlang. The two have already been combined: http://www.erlang-factory.com/conference/SFBay2011/speakers/...
It's interesting to see Kaspersky suggest that the state is behind this solely based on some unknown code. Does anyone know why that would be a likely conclusion on their part?
Just wait until they let the A.I. make the language as so it is not human decipherable.
http://www.kurzweilai.net/ai-designs-its-own-video-game
Pretty much, let the machine make the code.