Russian lab reports major malware discovery

MOSCOW — In what is being called a new hunt for Red October, a Russian cyber-security company says it has found a major international malware system that has attacked and compromised the computers of government agencies, diplomatic consulates, research centers and defense installations, among other sensitive institutions.

The malware has siphoned off terabytes’ worth of information, much of it classified, researchers with Moscow-based Kaspersky Lab said in a report this week. The origin of the program and the motives of the attackers remain elusive, but there are hints that the programmers are Russian, the report says.

“Last October we first received from our clients samples of something we soon gathered was not just a malware program but a multi-component attack platform, initially targeting embassies around the world,” Vitaly Kamlyuk, a senior anti-virus expert at Kaspersky, said Wednesday. “We called the virus ‘Red October’ because we detected it in October and because it required a level of red-alert attention to tackle.”

Similar to the Flame virus, a now-defunct spyware program Kaspersky thwarted last year, the new virus usually infiltrates computers through an email attachment camouflaged to mimic ordinary business correspondence, the expert said.

“One embassy was looking to buy a car and received the virus in a car sale proposal they soon found in their inbox,” Kamlyuk said.

Kaspersky, a leading developer of commercial anti-virus software, said it found victims of the malware with IP addresses in 39 countries, led by Switzerland, Kazakhstan and Greece. The most common targets included embassies, government agencies and research institutes, as well as aerospace and energy companies.

Kaspersky said the malware was probably being operated by a government or criminal organization large enough to employ at least two dozen highly trained programmers.

Independent experts in the United States offered differing views on who might be responsible.

“The two primary suspects for this operation would have been either Russia or China, just based on some of the data,” said John Bumgarner, research director for the U.S. Cyber Consequences Unit, a nongovernmental think tank.

But researcher Jeffrey Carr, author of “Inside Cyber Warfare,” theorized that the malware was the work of the foreign intelligence service of a NATO or European Union country, and that the intent was to spy on Russian embassies.

“It’s a pretty good guess” that Russia’s spy service, the FSB, approached Kaspersky and asked the firm to investigate, Carr said. “One of the indications was that they were specifically looking for Russian documents.”

Kaspersky researchers said the spyware, when first installed, might be only several hundred kilobytes in size, minuscule by modern computer standards. But as it gets established and communicates with its controllers, it may grow to several megabytes.

The virus records the names of the users, their IP addresses, information stored on their processors and local disks, the history of browsers, logins and passwords, and the records of devices plugged into USB ports, including smartphones, according to the report.

Like the Flame program, the new virus can record screen shots, as well as keystrokes.

Evidence of the Red October virus dates to May 2007, Kamlyuk said. The program was embedded in Microsoft Excel and Word documents that had been used by Chinese hackers against Asian companies and Tibetan political activists, Kamlyuk said.

“But soon enough,” he said, “we realized that, despite its obvious Chinese roots and the fact that no agencies in China were in fact targets of the new malicious program, the Chinese hackers had nothing to do with Red October.”

The language used in the malware was primarily English, but not that of a native English speaker. It included Cyrillic symbols and transliterations of terms from Russian computer jargon, the researchers said.

For instance, Kamlyuk said, the malware sometimes uses the Russian word “zakladka” for “bookmark” or “marker” and “proga” for “programs.”

“Many domain names of the malware were registered under fake Russian names and addresses too,” he said.

“Now we have come to the realization that we are dealing with something programmed by Russian-speaking experts, based on Chinese hackers’ exploit documents and mostly aimed at embassies of and other targets in Russia and its former Soviet satellites,” Kamlyuk said.

Sergei Karaganov, honorary chairman of the Council on Foreign and Defense Policy, a Moscow-based think tank, said in an interview that such cyber-espionage is increasingly common and that Russia and other countries have attempted to create international protocols to combat it.

“But every time, their attempts have been thwarted by the stiff resistance on the part of the United States, which probably counts too much on its supremacy in this sphere,” he said. “On the other hand, I wouldn’t rule out the possibility of this being an ingenious trick on the part of Kaspersky Lab to boost their trade.”

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Local News

A firefighter stands in silence before a panel bearing the names of L. John Regelbrugge and Kris Regelbrugge during the ten-year remembrance of the Oso landslide on Friday, March 22, 2024, at the Oso Landslide Memorial in Oso, Washington. (Ryan Berry / The Herald)
‘Flood of emotions’ as Oso Landslide Memorial opens on 10th anniversary

Friends, family and first responders held a moment of silence at 10:37 a.m. at the new 2-acre memorial off Highway 530.

Julie Petersen poses for a photo with images of her sister Christina Jefferds and Jefferds’ grand daughter Sanoah Violet Huestis next to a memorial for Sanoah at her home on March 20, 2024 in Arlington, Washington. Peterson wears her sister’s favorite color and one of her bangles. (Annie Barker / The Herald)
‘It just all came down’: An oral history of the Oso mudslide

Ten years later, The Daily Herald spoke with dozens of people — first responders, family, survivors — touched by the deadliest slide in U.S. history.

Victims of the Oso mudslide on March 22, 2014. (Courtesy photos)
Remembering the 43 lives lost in the Oso mudslide

The slide wiped out a neighborhood along Highway 530 in 2014. “Even though you feel like you’re alone in your grief, you’re really not.”

Director Lucia Schmit, right, and Deputy Director Dara Salmon inside the Snohomish County Department of Emergency Management on Friday, March 8, 2024, in Everett, Washington. (Ryan Berry / The Herald)
How Oso slide changed local emergency response ‘on virtually every level’

“In a decade, we have just really, really advanced,” through hard-earned lessons applied to the pandemic, floods and opioids.

Ron and Gail Thompson at their home on Monday, March 4, 2024 in Oso, Washington. (Olivia Vanni / The Herald)
In shadow of scarred Oso hillside, mudslide’s wounds still feel fresh

Locals reflected on living with grief and finding meaning in the wake of a catastrophe “nothing like you can ever imagine” in 2014.

Rep. Suzan DelBene, left, introduces Xichitl Torres Small, center, Undersecretary for Rural Development with the U.S. Department of Agriculture during a talk at Thomas Family Farms on Monday, April 3, 2023, in Snohomish, Washington. (Olivia Vanni / The Herald)
Under new federal program, Washingtonians can file taxes for free

At a press conference Wednesday, U.S. Rep. Suzan DelBene called the Direct File program safe, easy and secure.

Former Snohomish County sheriff’s deputy Jeremie Zeller appears in court for sentencing on multiple counts of misdemeanor theft Wednesday, March 27, 2024, at Snohomish County Superior Court in Everett, Washington. (Ryan Berry / The Herald)
Ex-sheriff’s deputy sentenced to 1 week of jail time for hardware theft

Jeremie Zeller, 47, stole merchandise from Home Depot in south Everett, where he worked overtime as a security guard.

Everett
11 months later, Lake Stevens man charged in fatal Casino Road shooting

Malik Fulson is accused of shooting Joseph Haderlie to death in the parking lot at the Crystal Springs Apartments last April.

T.J. Peters testifies during the murder trial of Alan Dean at the Snohomish County Courthouse on Tuesday, March 26, 2024 in Everett, Washington. (Olivia Vanni / The Herald)
Bothell cold case trial now in jury’s hands

In court this week, the ex-boyfriend of Melissa Lee denied any role in her death. The defendant, Alan Dean, didn’t testify.

A speed camera facing west along 220th Street Southwest on Tuesday, Nov. 21, 2023 in Edmonds, Washington. (Olivia Vanni / The Herald)
New Washington law will allow traffic cams on more city, county roads

The move, led by a Snohomish County Democrat, comes as roadway deaths in the state have hit historic highs.

Mrs. Hildenbrand runs through a spelling exercise with her first grade class on the classroom’s Boxlight interactive display board funded by a pervious tech levy on Tuesday, March 19, 2024 in Marysville, Washington. (Olivia Vanni / The Herald)
Lakewood School District’s new levy pitch: This time, it won’t raise taxes

After two levies failed, the district went back to the drawing board, with one levy that would increase taxes and another that would not.

Alex Hanson looks over sections of the Herald and sets the ink on Wednesday, March 30, 2022 in Everett, Washington. (Olivia Vanni / The Herald)
Black Press, publisher of Everett’s Daily Herald, is sold

The new owners include two Canadian private investment firms and a media company based in the southern United States.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.