The telephone call came on 1 September 2011. Boldizsár Bencsáth, a researcher at the Laboratory of Cryptography and System Security — CrySyS Lab — at the Budapest University of Technology and Economics, was asked by the chief executive of a company the laboratory sometimes consulted for — named only by a pseudonym in Kim Zetter's later account — whether he had time to look at something. They thought they had been broken into. On the client's machines Bencsáth found encrypted files written late at night on developers' computers, waiting to be collected, then more infected machines across the network. Every temporary file it left behind began with the characters ~DQ, and the laboratory called it Duqu. On 14 October the Hungarians emailed their findings to Symantec; on 18 October Symantec published them.
What the code did was watch. Symantec called it "nearly identical to Stuxnet, but with a completely different purpose" — an information-stealer whose job, in its reading, was to gather material from entities such as industrial control system manufacturers so that a later attack on a third party would be easier. The keylogger carried a JPEG inside itself — a partial NASA image labelled "Interacting Galaxy System NGC 6745", with an encrypted library holding the logging code tucked in behind it — and wrote keystrokes, passwords, documents and screenshots into encrypted temporary files for collection. A kill date in the configuration destroyed the installation after thirty-six days. One kernel driver carried a valid digital signature in the name of C-Media Electronics of Taipei, revoked on 14 October 2011 by Symantec's account; researchers argued then and since over whether the key had been stolen or simply issued by an authority that should have checked.
The delivery was a Microsoft Word document exploiting an unpatched flaw in the TrueType font parsing engine that then sat inside the Windows kernel. Microsoft issued an advisory and workaround on 3 November 2011 and shipped the fix, MS11-087, on 13 December, crediting Symantec and the Hungarian laboratory for CVE-2011-3402. The command servers were rented CentOS machines — one at a hosting company in Mumbai, one in Belgium, others in Vietnam, Germany and the Netherlands — each with its OpenSSH quietly upgraded and set to tunnel traffic onward to a machine nobody found. Kaspersky Lab went through them and found one broken into as early as November 2009, and every server wiped on 20 October 2011 — a root folder on one stamped at seven minutes past six that evening.
Nobody has ever claimed Duqu. Symantec and Kaspersky both argued common authorship with Stuxnet, from shared code, driver signing and injection method; Dell SecureWorks published a dissent on 26 October 2011, holding the supporting evidence "circumstantial at best and insufficient to confirm a direct relationship". ICS-CERT, whose first alert went out on the day of Symantec's paper, concluded in the end that neither industrial control systems nor their makers had been targeted at all. Symantec's own count of confirmed infections reached eight countries — France, the Netherlands, Switzerland, Ukraine, India, Iran, Sudan and Vietnam — across six organisations: a handful, not a campaign, and traceable, it cautioned, only as far as an internet provider. In March 2012 Kaspersky asked programmers publicly to identify a block of code it could not place, and was told it was plain C, compiled for size, with a hand-rolled object-oriented extension.
Three days without messages
The failure began on the morning of Monday 10 October 2011, and by that afternoon BlackBerry users across Europe, the Middle East and Africa had no email, no browsing and no BlackBerry Messenger. Research In Motion said a core switch inside its own infrastructure had failed and that the failover to a back-up switch "did not function as previously tested," leaving a large backlog of data; reporters traced the switch to RIM's data centre at Slough, west of London. The company's own list of cut-off regions grew on the Tuesday to include India, Brazil, Chile and Argentina, and on the Wednesday the delays reached North America. Service was declared fully restored on Thursday 13 October, three days in, across a subscriber base RIM then put at about seventy million. Mike Lazaridis, its co-chief executive, recorded a video message: "You've depended on us for reliable, real-time communications, and right now we're letting you down." On 17 October RIM offered customers more than $100 of premium applications through BlackBerry App World, available from the 19th, and enterprise customers a free month of technical support.
Borrowed lists, boards and a parliament
Between 7 and 10 October somebody tested a large set of sign-in identifiers and passwords against Sony's networks. About 93,000 matched: roughly 60,000 on PlayStation Network and Sony Entertainment Network, some 33,000 on Sony Online Entertainment. In a statement of 12 October Sony's chief information security officer, Philip Reitinger, said those accounts had been locked, card numbers were not at risk, and the overwhelming majority of attempts had failed — evidence, he took it, that the list came from elsewhere. On 20 October Reuters reported, citing people familiar with an FBI and NSA investigation, that whoever was inside Nasdaq's Directors Desk — a board-papers service breached by October 2010, disclosed in February 2011 — had planted software to read directors' communications before it was found; Nasdaq maintained its trading systems were untouched. On 25 October the Asahi Shimbun reported that an attachment opened in a lower-house office in late July had given a server in China a month's reach over the email of Japan's 480 members and their staff; the day before, that a defence contractor whose intrusion it had disclosed in September now had evidence that fighter-aircraft and nuclear-plant material had left its network.
The server in Mumbai
Symantec told a hosting company in Mumbai that one of its servers was talking to machines infected with Duqu. Web Werks — privately held, about two hundred staff — could not say who had leased the virtual server. "We couldn't track down this customer," an employee told Reuters, which carried the affair on 28 October 2011; officials from the Department of Information Technology took away hard drives and other components. Gulshan Rai, then the director of CERT-In, said only that he was not able to comment on any investigations. Kaspersky Lab, going through the surviving images, judged the Indian machine copied too late: everything had been wiped on 20 October. India appeared twice over — as a command server's address, and among the eight countries with confirmed infections.
The month's other Indian threads ran on paper. RIM's own list of regions cut off by the Slough switch named India, and subscribers here lost messaging for days while the government's long argument with the company over lawful interception went on in the background; that quarrel produced a promise of access only in February 2012, and a demonstration the government called satisfactory later still. Then on 26 October, at the sixty-sixth session of the United Nations General Assembly, India proposed a United Nations Committee for Internet-Related Policies: fifty member states meeting yearly in Geneva, four advisory groups for civil society, business, intergovernmental bodies and the technical community, reporting to the Assembly itself. Critics in Delhi and abroad read it as seating governments where ICANN had seated everybody else, and nothing came of it. Nothing in October 2011 obliged anyone in India to report an intrusion to anyone at all; since April 2022 there has been a six-hour clock.
Siri ships in beta, Iris in eight hours
Apple introduced the iPhone 4S on 4 October 2011 and, with it, Siri — in Apple's words "an intelligent assistant that helps you get things done" — and shipped it, marked beta, when the handset reached seven countries on 14 October. It understood English localised for the United States, Britain and Australia, plus French and German; it placed calls, sent messages, set reminders and read out the weather, and did almost none of it on the handset, sending recorded speech to Apple's servers instead. The recognition engine was Nuance's, which neither company confirmed until Nuance's chief executive, Paul Ricci, said so in 2013. Apple had bought Siri in April 2010 from a company spun out of SRI International, where the work grew out of the DARPA-funded CALO programme. A fortnight later a team at Dexetra, a start-up in Kochi, built an Android reply in about eight hours at a hackathon and called it Iris, for Intelligent Rival Imitator of Siri. The arrangement Siri fixed — microphone on the handset, model in a data centre — is the one assistants have used ever since.
Security moves below the operating system
At its FOCUS conference in Las Vegas on 18 October 2011 McAfee announced Deep Defender and Deep Command, the first products built on DeepSAFE, the layer it had developed with Intel, its new owner, to sit beneath the operating system and watch memory and the processor for kernel rootkits; its co-president Todd Gebhart said malware could not be hidden "when interacting with the hardware, memory or operating system". On 14 October Kaspersky Lab launched Endpoint Security 8 for Windows and Security Center 9 in New York, gathering application control and whitelisting, device control and web filtering under one console fed by its cloud reputation network. On 31 October Symantec published its paper on the Nitro attacks, tracing spear-phished Poison Ivy through at least forty-eight chemical, advanced-materials and defence companies between late July and mid-September to a rented server in the United States run by a man in his twenties in Hebei province, whose involvement it could not confirm. The console and the named campaign became routine; security in silicon did not, and Intel sold control of McAfee in 2017.
⏳ Time capsule — October 2011
- On 5 October Steve Jobs died at his home in Palo Alto, California, aged fifty-six, of respiratory arrest caused by the pancreatic neuroendocrine tumour diagnosed in 2003; he had resigned as Apple's chief executive that August, and Tim Cook had taken the job.
- On 7 October the Norwegian Nobel Committee announced that the Peace Prize would be shared by Ellen Johnson Sirleaf, the president of Liberia, the Liberian campaigner Leymah Gbowee and the Yemeni activist Tawakkol Karman, "for their non-violent struggle for the safety of women and for women's rights to full participation in peace-building work".
- Thailand's worst floods in decades, which took a heavy human toll, reached the industrial estates north of Bangkok during October and closed the hard disk assembly plants at Bang Pa-In and Navanakorn; about a quarter of the world's drive assembly capacity sat in Thailand, and by one price-comparison site's measure average selling prices rose about 151 per cent between 1 October and 14 November.
- On 31 October the United Nations marked its Day of Seven Billion, the date it had picked for world population passing that figure, with an acknowledged error of about a year either way; Plan International handed a birth certificate to a newborn girl in Uttar Pradesh in protest at sex-selective abortion, and a baby in Manila was named the symbolic seven-billionth.
The relative that came back
Duqu set the pattern that has held since: reconnaissance first, sabotage only if wanted, a kill date so the tooling leaves before anyone thinks to look. That the family persisted was settled in June 2015, when Kaspersky found a successor in its own network. The lineage argument was never closed by anyone willing to be named: Kaspersky's account of Gauss in August 2012 put Duqu, Stuxnet and Flame in one factory, and the Olympic Games reporting of June 2012 named the governments behind Stuxnet, but no state has claimed Duqu and no court has assigned it. The flaw it rode in on was answered: from Windows 10 Microsoft moved font parsing out of the kernel into a restricted user-mode process, sandboxed from the 2016 Anniversary Update in a container with no capabilities at all.
The rest of the month aged into ordinary conditions. One switch taking messaging off four continents is the textbook case for testing a failover, not assuming it; RIM renamed itself BlackBerry in 2013, left handset making in 2016, and on 4 January 2022 switched off the legacy services, so the devices silenced for three days in 2011 fell silent for good. Sony's borrowed list was an early instance of what the trade now calls credential stuffing, no longer an incident but a weather condition; the defences took most of the following decade to become normal. India's part was infrastructure rather than target: a leased server, an untraceable customer, hard drives carried out of a data centre, no statute to say what anyone owed anybody. A privacy law arrived only in 2023, with the DPDP Act.