
One of the most difficult computer viruses ever found was aimed at undermining objects of civil infrastructure in Iran. The harmful program turned out to be so difficult that the power of the whole state should have been behind its development, BBC experts say.
The self -reproduced Stuxnet virus is aimed at objects not of virtual, but the real world, such as power plants, watering stations and industrial facilities. The virus was first discovered in June by a Belarusian company, since then it has been carefully examined. But perhaps he has been circulating since 2009. According to the British newspaper The Daily Mail , it has already struck about 45 thousand networks in various countries of the world.
“Since there are much more cases of infection with this virus in Iran than anywhere else in the world, the virus was directed precisely against Iran, and in Iran there is something that was of a very great interest for the one who wrote it,” says Liam O'Murchu from Symantec. Iran accounted for about 60% of the infection. Many infections were also noted in India and Indonesia.
The assumptions are expressed that the virus could be aimed at nuclear power plants in the Bushera, the loading of fuel on which they started in August this year, or at the UNTAZE Uranus enrichment plant, where the second cascade of the Centrifug was commissioned , which, in violation of the UN Security Council, is more effectively enriched with Uranus. But O'Murchu and other experts believe that so far it has not been collected enough to draw conclusions both about the purpose of the spread of the virus and its compiler.
Unlike most other viruses, Stuxnet is designed to hit precisely those computer systems that are not connected to the Internet for security reasons. It is tolerated by means of USB electronic keys used to transfer files from one computer to another.
Having penetrated one of the computers of the internal network, he searches for a certain configuration of software that controls industrial facilities and developed by the German concern Siemens. Not finding this configuration, the virus remains relatively harmless. If he finds the desired program, he takes control of it and intercepts the management of industrial equipment.
Thus, the virus can turn on and off the engines, observe the temperature of the objects and adjust it by means of cooler and ultimately set such a sequence of commands to industrial equipment, which will lead to its destruction.
The complexity of the virus lies in new methods of shelter from antivirus programs and various methods of penetration into protected networks. He uses four previously detected gaps in the defense of the Windows operating system.
At the same time, cybercriminals and ordinary hackers are so highly appreciated by these gaps in Windows code that they would not spend them so wastefully, armed the same virus with means of using several of them at the same time, Mikko Hipponen, the main researcher of the F-Secure company explained. Since then, however, Microsoft has already corrected two of these four errors.
“With the testimonies that we now have, obviously and proving that Stuxnet is a direct intentional attack using a large array of insider information. This is not a hacker sitting in the basement of the parental house. It seems to me that the resources for organizing such an attack can only be placed by the state,” writes computer expert Ralph Langner. He believes that Stuxnet could be directed against nuclear power plants in the Bushera, but does not make final conclusions on this subject. Just in one photo taken inside the Bushera NPP, you can find the very computer systems for managing industrial equipment against which the virus was directed.
The representative of Siemens did not comment on the discussions of the genuine goals of the virus conducted by experts. He only said that the Bushersky nuclear power plant was completed with the help of a Russian contractor, and the equipment from Siemens was not used, and recalled that the concern ceased to cooperate with Iran about 30 years ago.
The concern is known only about 15 cases of virus penetration into industrial equipment management systems, mainly in Germany. At the same time, they did not affect the work of equipment, and in all cases the virus was destroyed. In addition, world security standards do not allow the use of Microsoft software to manage important production processes in enterprises.
This is not the first time to identify a computer virus designed to impress industrial infrastructure objects. In 2009, the US authorities recognized that they discovered a virus that could turn off the country's energy objects. In addition, according to Hipponen, a viral attack was organized on the military facilities of one of the NATO countries through the USB, but whether it became successful, experts do not know.
O'Murchu will publish his report in Virus Bulletin 2010, which will be released in Vancouver on September 29. Representatives of the Russian Kaspersky laboratory will also present their discoveries in the same area.