Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Duqu 2.0 malware buried into Windows PCs using stolen Foxconn certs (Signed by Chinese factory)
The Register ^ | June 15, 2015 | John Leyden

Posted on 06/15/2015 8:24:50 PM PDT by dayglored

The super-sophisticated malware that infiltrated Kaspersky Labs is more crafty than first imagined.

We're told that the Duqu 2.0 software nasty was signed using legit digital certificates issued to Foxconn – a world-leading Chinese electronics manufacturer, whose customers include Microsoft, Dell, Google, BlackBerry, Amazon, Apple, and Sony. The code-signing was uncovered by researchers at Kaspersky Lab, who are studying their Duqu 2.0 infection.

Windows trusts Foxconn-signed code because the Chinese goliath's certificate was issued by VeriSign, which is a trusted certificate root. Thus, the operating system will happily load and run the Foxconn-signed Duqu 2.0's 64-bit kernel-level driver without setting off any alarms. And that would allow the malware to get complete control over the infected machine.

Kaspersky Lab experts reckon Duqu's masterminds have been able to snatch copies of the private keys to various code-signing certificates, using a different one in each attack on an organization. The Foxconn certificate used in this instance was most likely stolen.

The Russian security firm said the Foxconn certificate leak undermines the use of digital certificates as a reliable tool for validating computer code: the whole point of them is to prove that software has not been tampered with, and was built by the vendor signing the executable.

...

As previously reported, Duqu 2.0 exploits up to three zero-day vulnerabilities, marking it out as sophisticated and likely the work of an intelligence agency – Israel's spies are suspected. Duqu 2.0 resides solely in the computer’s memory, with no data written to disk....

(Excerpt) Read more at theregister.co.uk ...


TOPICS: Business/Economy; Computers/Internet; Hobbies
KEYWORDS: 201506; amazon; apple; blackberry; china; computers; computing; dell; duqu; duqu2; duqu20; foxconn; google; hacker; internet; israel; joooooooooooooooooos; kaspersky; kasperskylabs; malware; microsoft; russia; sony; tech; verisign; virus; windows; windowspinglist
Navigation: use the links below to view more comments.
first previous 1-2021-4041-44 last
To: __rvx86

>or purchase from an independent system integrator...

I am amazed there are any of those left.


41 posted on 02/28/2021 2:59:53 AM PST by FreedomPoster (Islam delenda est)
[ Post Reply | Private Reply | To 14 | View Replies]

To: The Free Engineer

Yeah, I wonder about things like my Bluetooth keyboard.


42 posted on 02/28/2021 3:04:15 AM PST by FreedomPoster (Islam delenda est)
[ Post Reply | Private Reply | To 28 | View Replies]

To: dayglored

Yes, it’s da Jooooooooooz.

/sarc


43 posted on 02/28/2021 3:09:44 AM PST by Tolerance Sucks Rocks (GOP-free since 10/9/20)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

America first. American internet first - freeze out scammers.


44 posted on 02/28/2021 10:05:07 AM PST by GOPJ (Was Jussie Smollett working for "Homeland Security" when he faked his hate crimes?)
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-44 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson