W32.Duqu: the precursor to the next stuxnet
Eric Chien, Liam O’Murchu, Nicolas Falliere · USENIX conference on Large-scale exploits and emergent threats · 2012
On October 14, 2011, we were alerted to a sample by the Laboratory of Cryptography and System Security (CrySyS) at Budapest University of Technology and Economics. The threat appeared very similar to the Stuxnet worm from June of 2010 [1]. CrySyS named the threat Duqu [dyu-kyu] because it creates files with the file name prefix “~DQ” [2]. We confirmed Duqu is a threat nearly identical to Stuxnet, but with a completely different purpose of espionage rather than sabotage.