Skip to main content

Backdoor:W32/Duqu

Classification

Category:

Malware

Type:

Backdoor

Aliases:

  • Backdoor:W32/Duqu
  • Backdoor:W32/Duqu.A
  • Backdoor:W32/Duqu.B w32.Duqu (Symantec)

Summary

Backdoor:W32/Duqu silently installs files on the infected system, then collects and forwards the confidential information from the system to a remote Command and Control (CC) server. Duqu is reportedly targeted to specific organizations, possibly with a view to collecting specific information that could be used for a later attack.

Removal

Technical Details

Backdoor:W32/Duqu's source code appears to be closely related to that of Stuxnet. Unlike Stuxnet, Duqu's payload appears to be related to information gathering.

Multiple Duqu variants have reportedly been identified, though functional similarities between all the variants have yet to be confirmed.

Installation

The A variant of this malware drops the following files:

  • %Windows%\system32\Drivers\jminet7.sys - loader driver componet
  • %SystemDrive%\inf\netp191.pnf - encrypted main DLL component
  • %SystemDrive%\inf\netp192.pnf - encrypted configuration file

Similar to Stuxnet, Duqu's driver files are signed with certificates stolen from a Taiwanese company.

The malware then creates the following launch point:

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\JmiNET3

The driver is loaded during system start-up and will be responsible for decrypting and loading the main DLL component.

The B variant of this malware uses different filenames (cmi4432.sys, cmi4432.pnf and cmi4464.PNF, respectively) and a differently-named launchpoint (HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmi4432), but further functionality appears to be the same.

Remote Communication

On successful installation, Duqu attempts to connect to a remote CC server, which may allow the attackers to update the installed components, download additional components onto the system, retrieve collected information and issue further commands.

It was reported that a standalone spying component (which we categorize as a trojan-spy) was recovered on an infected system. It was probably downloaded by the malware at some point in time. We detect the trojan-spy generically.

The trojan-spy is able to record keystrokes and collect various details of system information. The collected information is saved to an encrypted file, which the attackers can retrieve via the CC server.

Removal

Duqu is reportedly configured to run for 36 days, after which it will automatically remove itself from the system.

More

For more information, see:

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.