Duqu + Centos 5.x


Verified User
Jul 6, 2009
related to this article http://en.wikipedia.org/wiki/Duqu
i just wondered if you guys noticed something strange on your servers?

probably im a bit late about this but seams like there is no notification around here yet and i think its important to shared this info.

Command and control servers

Some of the command and control servers of Duqu have been analysed. It seems that the people running the attack had a predilection for CentOS 5.x servers, leading some researchers to believe that they had a zero-day exploit for it. Servers are scattered in many different countries, including Germany, Belgium, Philippines and China. Kaspersky published multiple blogpost on the command and control servers.