Don’t do SECURITY. Do business SECURELY.

Duqu malware found sharing code with Stuxnet

Symantec published analysis of Duqu, espionage malware found by Hungarian researchers that shared much of its code with Stuxnet.

Security firm Symantec published analysis of Duqu, a newly discovered piece of malware it described as a precursor to the next Stuxnet. The sample had been found by the CrySyS research lab in Hungary.

What happened

  • Researchers reported that Duqu shared significant portions of code with Stuxnet, suggesting the same authors or people with access to Stuxnet’s source code.
  • Unlike Stuxnet, Duqu appeared designed to gather intelligence, such as information that could support future attacks, rather than to cause physical damage.
  • Infections appeared limited to a small number of targeted organisations, and the malware was set to remove itself after a fixed period.
  • Researchers later found Duqu used a previously unknown Windows vulnerability, which Microsoft patched.

Why it mattered

Duqu suggested that the group behind Stuxnet remained active and was running wider espionage operations, reinforcing concerns about state-backed malware. It was the first of several related discoveries, followed by Flame in 2012.

Lessons for organisations

Targeted malware often goes undetected by traditional antivirus, so layered monitoring and threat intelligence sharing matter. Keep systems patched quickly when zero-day fixes are released.

Sources: Symantec (Broadcom), NBC News

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights