‘Red October’: Global cyber-spy network uncovered by Russian experts

‘Red October’: Global cyber-spy network uncovered by Russian experts

Published: 15 January, 2013, 05:56

A sophisticated cyber-espionage network targeting the world's diplomatic, government and research agencies has been uncovered by the Kaspersky Lab, whose experts say the malware's complexity could rival that of the notorious Flame virus.

­The system's targets include a wide range of countries, with the primary focus on Eastern Europe, former Soviet republics and Central Asia – although many in Western Europe and North America are also on the list.

In addition to attacking traditional computer workstations, Rocra – a shortened name for Red October, the name given the network by the Kaspersky team – can steal data from smartphones, dump network equipment configurations, snatch files from removable disk drives, including those that had been erased, and scan through email databases and local network FTP servers.  

Unlike other well-known highly automated cyber-espionage campaigns like Flame and Gauss, the Rorca's attacks all appear to be carefully chosen. Each operation is apparently driven by the configuration of the victim’s hardware and software, native language and even habit of document usage.

The information extracted from infected networks is often used to gain entry into additional systems. For example, stolen credentials were shown to be compiled in a list for use when attackers needed to guess passwords or phrases.

The hackers behind the network have created more than 60 domain names and several server hosting locations in different countries – the majority of those known being in Germany and Russia – which worked as proxies in order to hide the location of the “mothership” control server.

That server's location remains unknown.

Experts have uncovered over 1,000 modules belonging to 30 different module categories. While Rocra seems to have been designed to execute one-time tasks sent by the hackers’ servers, a number of modules were constantly present in the system executing persistent tasks. For example, retrieving information about a phone, its contact list, call history, calendar, SMS messages and even browsing history as soon as an iPhone or a Nokia phone is connected to the system.

The hackers' primary objective is to gather information and documents that compromised governments, corporations or other organizations and agencies. In addition to focusing on diplomatic and governmental agencies around the world, the hackers also attacked energy and nuclear groups and trade and aerospace targets.

No details have been given so far as to who the attackers could be. However, there is strong technical evidence to indicate that the attackers have Russophone origins, as Russian words including slang have been used in the source code commentaries. Many of the known attacks have taken place in Russian-speaking countries.

Views: 79

Reply to This

"Destroying the New World Order"

TOP CONTENT THIS WEEK

THANK YOU FOR SUPPORTING THE SITE!

mobile page

12160.info/m

12160 Administrators

 

Latest Activity

tjdavis posted a video

"The Chinese thought it was an elaborate joke" | Helen Joyce

John and Helen discuss why transgenderism and gender theory are a Western phenomenon.Helen Joyce was Britain Editor at The Economist, where she worked for ov...
35 minutes ago
Doc Vega posted blog posts
1 hour ago
Less Prone commented on tjdavis's photo
Thumbnail

iconism

"Germany remains a country under military occupation by its conqueror. US has 21 military bases and…"
1 hour ago
Larry Harmen's 2 blog posts were featured
2 hours ago
Doc Vega's 5 blog posts were featured
2 hours ago
cheeki kea's blog post was featured

Dr. Aseem Malhotra's Explosive Court Testimony on COVID "Vaccines"(UPDATED)

 Doctor Malhotra drops arsenal of truth bombs on Helsinki. A spectacular display. Here are few snip…See More
2 hours ago
FREEDOMROX's blog post was featured
2 hours ago
cheeki kea commented on Less Prone's photo
Thumbnail

Famine or War What Would it Be

"I think it will be famine for some and war for others. "
6 hours ago
cheeki kea commented on Sandy's photo
Thumbnail

FB_IMG_1710523455761

"Burbia is correct. The Tik of the litter is successful in gorging itself at the information/media…"
6 hours ago
Less Prone posted a video

How the Government Uses Fear-Mongering to Alter Your Brain

Unlock the full interview here: https://bit.ly/3RCq6ccMolecular geneticist and immunologist Dr. Michael Nehls tells Tucker Carlson how fear-mongering is used...
16 hours ago
Doc Vega posted a photo

main-qimg-5806e1adb3109cf42e236b6063e7e3ec

The cowardly murderous Democrats out to destroy America.
yesterday
Sandy posted videos
yesterday
Burbia commented on Sandy's photo
Thumbnail

FB_IMG_1710523455761

"Is that the narrative now? Its more like Tik Tok influenced the younger generation to not be…"
yesterday
Burbia commented on Less Prone's photo
Thumbnail

Rebuilding Khazaria

"Who exactly are these beings? They violently push their way into the Middle East claiming it their…"
yesterday
Less Prone posted a photo

Famine or War What Would it Be

How far are these monsters allowed to go?
Thursday
Less Prone favorited cheeki kea's blog post The saddest post I've ever read. ( vaccine victim speaks out. )
Thursday
Less Prone commented on cheeki kea's blog post The saddest post I've ever read. ( vaccine victim speaks out. )
"It's so cruel and unfair. So many innocent people fell for it and even now the wictims are…"
Thursday
Doc Vega commented on truth's video
Thumbnail

MSM Admits US Funding Al-Qaeda & Taliban Terror Attacks

"In all likelihood if the MSM comes up with an explanation it's probably pure unadulterated…"
Thursday
Doc Vega commented on truth's video
Thumbnail

MSM Admits US Funding Al-Qaeda & Taliban Terror Attacks

"Mark Levin talks about all the front groups funded by Soros that have provided revenue for the…"
Thursday
Doc Vega favorited cheeki kea's blog post The saddest post I've ever read. ( vaccine victim speaks out. )
Thursday

© 2024   Created by truth.   Powered by

Badges  |  Report an Issue  |  Terms of Service

content and site copyright 12160.info 2007-2019 - all rights reserved. unless otherwise noted