A week ago Kaspersky Lab made public the fact that they discovered a new and more advanced Duqu attack. The most interesting fact is that they discovered the infection on their own internal systems. Duqu was only spying on the R&D departments, and was not interested in sales or customer details. This was a very well targeted attack. Their main interests were Kaspersky Lab's Secure Operating System, Fraud Prevention, Security Network, and their Anti-APT solutions and services. Without a doubt, Kaspersky Lab was not the only one that was affected, as large attacks were connected to the P5+1 event and 70th anniversary event of the liberation of Auschwitz-Birkenau.

Count Dooku from Star Wars
The time and resources invested in developing an amazing threat like Duqu 2 were huge. Bottom line, even though we have sky-rocketing industry improvements to security (and more specifically cyber security), the cyber-attack innovations are also shocking.
This is a highly sophisticated attack even if we don't take into consideration the fact that the malware was packed as a driver, and signed with a digital certificate that was stolen from Hon Hai Precision Industry Co. Ltd., (also known as Foxconn Technology Group). For Stuxnet and Duqu 1, the attackers used digital signatures from Jmicron and Realtek. Which means that they are not using the same certificate twice, and moreover, the attackers have access to the certificates of important hardware manufacturers.

Image credit: Kaspersky Lab
The file portserv.sys (92E724291056A5E30ECA038EE637A23F) was actually the signed driver. Kaspersky Lab explains in an outstanding blog post the behavior and logic behind it. Duqu 2 is a very hot topic right now, and there are many blog posts and analysis online discussing it. Kaspersky Lab was kind enough to share a lot of details about it, and so I decided not to go with a deeper analysis of Duqu 2, but to concentrate more on the detection rates by the anti-malware community.
We ran the samples through Metascan Online, and were surprised to find that only 13 to 17 engines detected the samples as malware. So we rescanned the samples a few times in the following days to see how the engines handled this outbreak. 5 days later the response was far from ideal, with less than 70% of engines detecting the samples as malware! This surprised me, given the amount of press coverage Duqu 2 received.
As an example, we scanned sample 089A14F69A31EA5E9A5B375DC0C46E45 the day after the Kaspersky Lab announcement and 16/44 engines detected the threat.
The following day it reached detection by 24 engines and then 25 engines. I said to myself, "This may not be very impressive, but at least the detection rate is improving." However, three days later, only 2 more engines managed to detect the sample as malware. This response lag may be a crucial security issue for many organizations, as company secrets, employee details, banking information, and more can be stolen in a much shorter time period than three days.
Let me make our message clear- this demonstrates the true value of multi-scanning. We don't have a silver bullet and we don't pretend to. Nobody does; whoever promises you 100% threat protection, 100% of the time is lying. But by by joining forces the anti-malware community can stop infections faster and avoid security disasters.
At OPSWAT our goal isn't only to use the power of multiple engines, but to help the entire community. Through the Metascan Online Sample Sharing Program, we provide anti-malware vendors and researchers with a feed of samples from Metascan Online (if and only if the client doesn't have the private scanning flag enabled). This sample sharing feed is used to exchange zero day malware samples as well as to identify potential false positives and false negatives. OPSWAT collects threat and infection data through Metascan Online, and uses the information to decide what infection samples need to be shared with the antivirus research community. We believe that the faster the antivirus community informs one another, the better our efforts will be in securing endpoints against infections. For those in the anti-malware community, please help us help our fellow AV engine partners, users, and researchers by having your organization register to participate in our Malware Sharing Program, or utilize Metascan Online to scan all of your files for the latest cyber threats.


