Skip to main content

New zero-day Windows kernel vulnerability associated with Duqu Trojan

posted onNovember 2, 2011
by l33tdawg

In the continuing saga of the malware known as Duqu, CrySyS Lab at the Budapest University of Technology and Economics has announced it was able to acquire a copy of the "dropper" from one of the victims.

What is a dropper and what does this mean? A dropper is a term used by anti-virus researchers to denote a piece of code that is usually installed onto a computer to download further malicious components.

Droppers are typically very small, are designed to evade detection by anti-virus and can sometimes contain exploit code used to inject themselves onto the target computer. That is why this finding is important. Many analysts still have some doubts as to the relationship between Duqu and Stuxnet, but this piece of the chain of infection was missing. Now with a sample of the missing piece, we can put together a more coherent picture.

Source

Tags

Microsoft Viruses & Malware

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th