Russian lab reports major malware discovery

MOSCOW — In what is being called a new hunt for Red October, a Russian cyber-security company says it has found a major international malware system that has attacked and compromised the computers of government agencies, diplomatic consulates, research centers and defense installations, among other sensitive institutions.

The malware has siphoned off terabytes’ worth of information, much of it classified, researchers with Moscow-based Kaspersky Lab said in a report this week. The origin of the program and the motives of the attackers remain elusive, but there are hints that the programmers are Russian, the report says.

“Last October we first received from our clients samples of something we soon gathered was not just a malware program but a multi-component attack platform, initially targeting embassies around the world,” Vitaly Kamlyuk, a senior anti-virus expert at Kaspersky, said Wednesday. “We called the virus ‘Red October’ because we detected it in October and because it required a level of red-alert attention to tackle.”

Similar to the Flame virus, a now-defunct spyware program Kaspersky thwarted last year, the new virus usually infiltrates computers through an email attachment camouflaged to mimic ordinary business correspondence, the expert said.

“One embassy was looking to buy a car and received the virus in a car sale proposal they soon found in their inbox,” Kamlyuk said.

Kaspersky, a leading developer of commercial anti-virus software, said it found victims of the malware with IP addresses in 39 countries, led by Switzerland, Kazakhstan and Greece. The most common targets included embassies, government agencies and research institutes, as well as aerospace and energy companies.

Kaspersky said the malware was probably being operated by a government or criminal organization large enough to employ at least two dozen highly trained programmers.

Independent experts in the United States offered differing views on who might be responsible.

“The two primary suspects for this operation would have been either Russia or China, just based on some of the data,” said John Bumgarner, research director for the U.S. Cyber Consequences Unit, a nongovernmental think tank.

But researcher Jeffrey Carr, author of “Inside Cyber Warfare,” theorized that the malware was the work of the foreign intelligence service of a NATO or European Union country, and that the intent was to spy on Russian embassies.

“It’s a pretty good guess” that Russia’s spy service, the FSB, approached Kaspersky and asked the firm to investigate, Carr said. “One of the indications was that they were specifically looking for Russian documents.”

Kaspersky researchers said the spyware, when first installed, might be only several hundred kilobytes in size, minuscule by modern computer standards. But as it gets established and communicates with its controllers, it may grow to several megabytes.

The virus records the names of the users, their IP addresses, information stored on their processors and local disks, the history of browsers, logins and passwords, and the records of devices plugged into USB ports, including smartphones, according to the report.

Like the Flame program, the new virus can record screen shots, as well as keystrokes.

Evidence of the Red October virus dates to May 2007, Kamlyuk said. The program was embedded in Microsoft Excel and Word documents that had been used by Chinese hackers against Asian companies and Tibetan political activists, Kamlyuk said.

“But soon enough,” he said, “we realized that, despite its obvious Chinese roots and the fact that no agencies in China were in fact targets of the new malicious program, the Chinese hackers had nothing to do with Red October.”

The language used in the malware was primarily English, but not that of a native English speaker. It included Cyrillic symbols and transliterations of terms from Russian computer jargon, the researchers said.

For instance, Kamlyuk said, the malware sometimes uses the Russian word “zakladka” for “bookmark” or “marker” and “proga” for “programs.”

“Many domain names of the malware were registered under fake Russian names and addresses too,” he said.

“Now we have come to the realization that we are dealing with something programmed by Russian-speaking experts, based on Chinese hackers’ exploit documents and mostly aimed at embassies of and other targets in Russia and its former Soviet satellites,” Kamlyuk said.

Sergei Karaganov, honorary chairman of the Council on Foreign and Defense Policy, a Moscow-based think tank, said in an interview that such cyber-espionage is increasingly common and that Russia and other countries have attempted to create international protocols to combat it.

“But every time, their attempts have been thwarted by the stiff resistance on the part of the United States, which probably counts too much on its supremacy in this sphere,” he said. “On the other hand, I wouldn’t rule out the possibility of this being an ingenious trick on the part of Kaspersky Lab to boost their trade.”

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Local News

In this Jan. 4, 2019 photo, workers and other officials gather outside the Sky Valley Education Center school in Monroe, Wash., before going inside to collect samples for testing. The samples were tested for PCBs, or polychlorinated biphenyls, as well as dioxins and furans. A lawsuit filed on behalf of several families and teachers claims that officials failed to adequately respond to PCBs, or polychlorinated biphenyls, in the school. (AP Photo/Ted S. Warren)
Judge halves $784M for women exposed to Monsanto chemicals at Monroe school

Monsanto lawyers argued “arbitrary and excessive” damages in the Sky Valley Education Center case “cannot withstand constitutional scrutiny.”

Mukilteo Police Chief Andy Illyn and the graphic he created. He is currently attending the 10-week FBI National Academy in Quantico, Virginia. (Photo provided by Andy Illyn)
Help wanted: Unicorns for ‘pure magic’ career with Mukilteo police

“There’s a whole population who would be amazing police officers” but never considered it, the police chief said.

Alan Edward Dean, convicted of the 1993 murder of Melissa Lee, professes his innocence in the courtroom during his sentencing Wednesday, April 24, 2024, at Snohomish County Superior Court in Everett, Washington. (Ryan Berry / The Herald)
Bothell man gets 26 years in cold case murder of Melissa Lee, 15

“I’m innocent, not guilty. … They planted that DNA. I’ve been framed,” said Alan Edward Dean, as he was sentenced for the 1993 murder.

People hang up hearts with messages about saving the Clark Park gazebo during a “heart bomb” event hosted by Historic Everett on Saturday, Feb. 17, 2024 in Everett, Washington. (Olivia Vanni / The Herald)
Clark Park gazebo removal complicated by Everett historical group

Over a City Hall push, the city’s historical commission wants to find ways to keep the gazebo in place, alongside a proposed dog park.

A person turns in their ballot at a ballot box located near the Edmonds Library in Edmonds, Washington on Sunday, Nov. 5, 2023. (Annie Barker / The Herald)
Deadline fast approaching for Everett property tax measure

Everett leaders are working to the last minute to nail down a new levy. Next week, the City Council will have to make a final decision.

Hawthorne Elementary students Kayden Smith, left, John Handall and Jace Debolt use their golden shovels to help plant a tree at Wiggums Hollow Park  in celebration of Washington’s Arbor Day on Wednesday, April 13, 2022 in Everett. (Olivia Vanni / The Herald)
Snohomish County to hold post-Earth Day recycling event in Monroe

Locals can bring hard-to-recycle items to Evergreen State Fair Park. Accepted items include Styrofoam, electronics and tires.

A group including Everett Mayor Cassie Franklin, Compass Health CEO Tom Sebastian, Sen. Keith Wagoner and Rep. Julio Cortes take their turn breaking ground during a ceremony celebrating phase two of Compass Health’s Broadway Campus Redevelopment project Thursday, Oct. 12, 2023, in Everett, Washington. (Ryan Berry / The Herald)
Compass Health cuts child and family therapy services in Everett

The move means layoffs and a shift for Everett families to telehealth or other care sites.

Everett
Everett baby dies amid string of child fentanyl overdoses

Firefighters have responded to three incidents of children under 2 who were exposed to fentanyl this week. Police were investigating.

Everett
Everett police arrest different man in fatal pellet gun shooting

After new evidence came to light, manslaughter charges were dropped against Alexander Moseid. Police arrested Aaron Trevino.

A Mukilteo Speedway sign hangs at an intersection along the road on Sunday, April 21, 2024, in Mukilteo, Washington. (Ryan Berry / The Herald)
What’s in a ‘speedway’? Mukilteo considers renaming main drag

“Why would anybody name their major road a speedway?” wondered Mayor Joe Marine. The city is considering a rebrand for its arterial route.

Edmonds City Council members answer questions during an Edmonds City Council Town Hall on Thursday, April 18, 2024 in Edmonds, Washington. (Olivia Vanni / The Herald)
Edmonds fire service faces expiration date, quandary about what’s next

South County Fire will end a contract with the city in late 2025, citing insufficient funds. Edmonds sees four options for its next step.

House Transportation Subcommittee Chairman Rep. Rick Larsen, D-Wash., speaks during a hearing on Capitol Hill in Washington, Wednesday, May 15, 2019, on the status of the Boeing 737 MAX aircraft.(AP Photo/Susan Walsh)
How Snohomish County lawmakers voted on TikTok ban, aid to Israel, Ukraine

The package includes a bill to ban TikTok if it stays in the hands of a Chinese company, which made one Everett lawmaker object.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.