Monday, April 25, 2011

Cyber Attack- Iran Finds Second Virus- Stars

Iran has identified a second virus that they have named 'Stars', Yahoo reports. The head of the Iranian military unit in charge of combatting sabotage, Gholam Reza Jalali, says that their experts have not finalized the analysis of the "espionage virus" they call "Stars". Jalali did not report what facilities or equipment the malware targeted or when it was first detected.

Jalali, head of the "Passive Defense" unit dealing mainly with counter sabotage, downplayed the payload, a virus term meaning the destructive properties of the malware. Jalali did report that initially the virus would deliver minimal damage and the file may be mistaken for executable government organization files.

Jalali also reports that a second unit has been setup by Iran's Ministry of Information Technology and Telecommunications to disseminate the malware and fully examine the delivery and payload of the destructive virus.

Last year, Stuxnet, a powerfully destructive worm, hit the nuclear facilities in Iran that had the potential to completely shut down the centrifuges that make the uranium. Iran has said it has identified the malware/virus/worm authors as coming from two countries, the United States and Israel. Jalali reports that Stuxnet had the ability to cause a large-scale industrial accident and the potential for loss of life.

Stuxnet's payload was to play back pre-recorded data that was then monitored by machine and human while the centrifuges starting spinning faster and faster that would overload the physical machines and cause overheating and eventual failure.

PC Virus Doctors wonders if the name "Stars" for the virus was actually what they saw when they discovered the malware residing on the Iranian computers.

No comments: