Friday, May 25, 2018

What is Stuxnet Virus and how does it work?

What is Stuxnet Virus?

Stuxnet worm is a rootkit exploit that targets supervisory control and data acquisition (SCADA) systems. SCADA systems are used widely for industrial control systems, such as power, water and sewage plants, as well as in telecommunications and oil and gas refining.
At the beginning, when this piece of malware was first discovered its purpose wasn't fully understood, but it was clear its design was complex, and it probably could not have been written without a team of expert programmers working over a period of several months.

How does it work?

Like most other viruses, Stuxnet spreads via the internet and on USB sticks. And the way it does this is not particularly clever or well hidden. To reach its target, Stuxnet needs to spread via USB sticks, allowing it to penetrate industrial systems disconnected from the Internet and thought to be safe from malware. However, apparent mistakes mean it also spreads via the internet.
Once Stuxnet had infected a computer, the worm could copy itself to any flash drives subsequently connected to the computer, and then spread from those flash drives to other computers.

What is so special about Stuxnet Virus?

Like the Zeus banking Trojan, Stuxnet code covered its tracks using stolen digital certificates to trick the operating system into letting Stuxnet install a rootkit. The malware could also avoid detection by traditional intrusion detection systems (IDS).
It is believed that Stuxnet was not designed for espionage, but rather to wipe out a large portion of Iran's nuclear centrifuges.
Stuxnet was designed to limit the acceleration of its spread by infecting a maximum of three computers from a single flash drive. Additionally, Stuxnet was very good at hiding on systems.

Who was Stuxnet aimed at?

Even though the Stuxnet makers included measures to limit its spread, something went wrong.
Stuxnet was aimed at a specific target list; it was designed to infiltrate heavy-duty industrial control programs that monitor and manage factories, oil pipelines, power plants and other critical installations, but somehow it spread to thousands of PCs outside Iran, in countries such as China and Germany, Kazakhstan and Indonesia.

How to remove Stuxnet from a PC?

