‘Red October’: Global cyber-spy network uncovered by Russian experts

‘Red October’: Global cyber-spy network uncovered by Russian experts

Published: 15 January, 2013, 05:56

A sophisticated cyber-espionage network targeting the world's diplomatic, government and research agencies has been uncovered by the Kaspersky Lab, whose experts say the malware's complexity could rival that of the notorious Flame virus.

­The system's targets include a wide range of countries, with the primary focus on Eastern Europe, former Soviet republics and Central Asia – although many in Western Europe and North America are also on the list.

In addition to attacking traditional computer workstations, Rocra – a shortened name for Red October, the name given the network by the Kaspersky team – can steal data from smartphones, dump network equipment configurations, snatch files from removable disk drives, including those that had been erased, and scan through email databases and local network FTP servers.  

Unlike other well-known highly automated cyber-espionage campaigns like Flame and Gauss, the Rorca's attacks all appear to be carefully chosen. Each operation is apparently driven by the configuration of the victim’s hardware and software, native language and even habit of document usage.

The information extracted from infected networks is often used to gain entry into additional systems. For example, stolen credentials were shown to be compiled in a list for use when attackers needed to guess passwords or phrases.

The hackers behind the network have created more than 60 domain names and several server hosting locations in different countries – the majority of those known being in Germany and Russia – which worked as proxies in order to hide the location of the “mothership” control server.

That server's location remains unknown.

Experts have uncovered over 1,000 modules belonging to 30 different module categories. While Rocra seems to have been designed to execute one-time tasks sent by the hackers’ servers, a number of modules were constantly present in the system executing persistent tasks. For example, retrieving information about a phone, its contact list, call history, calendar, SMS messages and even browsing history as soon as an iPhone or a Nokia phone is connected to the system.

The hackers' primary objective is to gather information and documents that compromised governments, corporations or other organizations and agencies. In addition to focusing on diplomatic and governmental agencies around the world, the hackers also attacked energy and nuclear groups and trade and aerospace targets.

No details have been given so far as to who the attackers could be. However, there is strong technical evidence to indicate that the attackers have Russophone origins, as Russian words including slang have been used in the source code commentaries. Many of the known attacks have taken place in Russian-speaking countries.

Views: 84

Reply to This

"Destroying the New World Order"

TOP CONTENT THIS WEEK

THANK YOU FOR SUPPORTING THE SITE!

mobile page

12160.info/m

12160 Administrators

 

Latest Activity

Doc Vega commented on Doc Vega's blog post Ashrams and Moonies Perfect Case for Mind Control
"less prone, Thanks for your support Buddy! "
2 hours ago
Doc Vega posted a photo

main-thumb-ti-6724328-100-cnsgqkrgkrhyeyyerazynmuwoplecnbx

When will they put Trump on Mt. Rushmore?
3 hours ago
Doc Vega's 4 blog posts were featured
12 hours ago
Burbia's blog post was featured

Charlie Kirk Assassination

September 10th 2025 in Utah Turning Point USA CEO has been assassinated. Coincidentally,  answering…See More
12 hours ago
Charles Magus's blog post was featured

FURTHER PROOF OF WALK-INS! Prisoners of the Dulce Base by Sherry Shriner

There is a real connection between the Cabal and what is happening at this Undergroung…See More
12 hours ago
Less Prone favorited Doc Vega's blog post Ashrams and Moonies Perfect Case for Mind Control
12 hours ago
Less Prone commented on tjdavis's blog post Sentient World Simulation
"Cannot open the link"
12 hours ago
Tina Sullivan is now a member of 12160 Social Network
17 hours ago
Doc Vega posted blog posts
yesterday
Sandy posted a video

We’re cooked

We’re cooked
yesterday
Sandy posted a photo
yesterday
tjdavis posted a video

Tom Horn discusses Masonic view of 2025

Startling perspective by Tom Horn of the upcoming year: 2025
yesterday
cheeki kea posted a photo
Tuesday
cheeki kea commented on Doc Vega's blog post Grooming the New Generation of Assassins
"It's a distressing state of affairs when evil leftists hardwire impressionable students and…"
Tuesday
Doc Vega commented on Doc Vega's blog post This Memorable Anthem Given by Nick Freitas Hit the Nail on the Head Please Listen!
"Burbia Charlie Kirk's wife is a real firebrand! God bless that poor woman! "
Monday
Doc Vega commented on Doc Vega's blog post This Memorable Anthem Given by Nick Freitas Hit the Nail on the Head Please Listen!
"Burbia thanks for the videos! "
Monday
Doc Vega posted blog posts
Monday
Burbia commented on tjdavis's video
Thumbnail

Charlie Kirk: Grief And Outrage From Turning Point USA in Phoenix

"Early reports said a.second shooter was there. Talk of Dischord chats. Peyton Gendron was coerced…"
Monday
tjdavis posted a video

America In Crisis: Illegals and Drug Smugglers Have Us Beat

An inside look at how bad the situation is at the Arizona/Mexico border. This exclusive tour with retired Arizona Sheriff Mark Lamb reveals just how bad thin...
Monday
Burbia posted a video

Sam Hyde Show: This is You

support the show: https://www.mde.tv/▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬🔥 BUY EXTREME PEACE on MDE.TV 🔥https://www.mde.tv/series/extreme-peace▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬...
Monday

© 2025   Created by truth.   Powered by

Badges  |  Report an Issue  |  Terms of Service

content and site copyright 12160.info 2007-2019 - all rights reserved. unless otherwise noted