Russian lab reports major malware discovery

MOSCOW — In what is being called a new hunt for Red October, a Russian cyber-security company says it has found a major international malware system that has attacked and compromised the computers of government agencies, diplomatic consulates, research centers and defense installations, among other sensitive institutions.

The malware has siphoned off terabytes’ worth of information, much of it classified, researchers with Moscow-based Kaspersky Lab said in a report this week. The origin of the program and the motives of the attackers remain elusive, but there are hints that the programmers are Russian, the report says.

“Last October we first received from our clients samples of something we soon gathered was not just a malware program but a multi-component attack platform, initially targeting embassies around the world,” Vitaly Kamlyuk, a senior anti-virus expert at Kaspersky, said Wednesday. “We called the virus ‘Red October’ because we detected it in October and because it required a level of red-alert attention to tackle.”

Similar to the Flame virus, a now-defunct spyware program Kaspersky thwarted last year, the new virus usually infiltrates computers through an email attachment camouflaged to mimic ordinary business correspondence, the expert said.

“One embassy was looking to buy a car and received the virus in a car sale proposal they soon found in their inbox,” Kamlyuk said.

Kaspersky, a leading developer of commercial anti-virus software, said it found victims of the malware with IP addresses in 39 countries, led by Switzerland, Kazakhstan and Greece. The most common targets included embassies, government agencies and research institutes, as well as aerospace and energy companies.

Kaspersky said the malware was probably being operated by a government or criminal organization large enough to employ at least two dozen highly trained programmers.

Independent experts in the United States offered differing views on who might be responsible.

“The two primary suspects for this operation would have been either Russia or China, just based on some of the data,” said John Bumgarner, research director for the U.S. Cyber Consequences Unit, a nongovernmental think tank.

But researcher Jeffrey Carr, author of “Inside Cyber Warfare,” theorized that the malware was the work of the foreign intelligence service of a NATO or European Union country, and that the intent was to spy on Russian embassies.

“It’s a pretty good guess” that Russia’s spy service, the FSB, approached Kaspersky and asked the firm to investigate, Carr said. “One of the indications was that they were specifically looking for Russian documents.”

Kaspersky researchers said the spyware, when first installed, might be only several hundred kilobytes in size, minuscule by modern computer standards. But as it gets established and communicates with its controllers, it may grow to several megabytes.

The virus records the names of the users, their IP addresses, information stored on their processors and local disks, the history of browsers, logins and passwords, and the records of devices plugged into USB ports, including smartphones, according to the report.

Like the Flame program, the new virus can record screen shots, as well as keystrokes.

Evidence of the Red October virus dates to May 2007, Kamlyuk said. The program was embedded in Microsoft Excel and Word documents that had been used by Chinese hackers against Asian companies and Tibetan political activists, Kamlyuk said.

“But soon enough,” he said, “we realized that, despite its obvious Chinese roots and the fact that no agencies in China were in fact targets of the new malicious program, the Chinese hackers had nothing to do with Red October.”

The language used in the malware was primarily English, but not that of a native English speaker. It included Cyrillic symbols and transliterations of terms from Russian computer jargon, the researchers said.

For instance, Kamlyuk said, the malware sometimes uses the Russian word “zakladka” for “bookmark” or “marker” and “proga” for “programs.”

“Many domain names of the malware were registered under fake Russian names and addresses too,” he said.

“Now we have come to the realization that we are dealing with something programmed by Russian-speaking experts, based on Chinese hackers’ exploit documents and mostly aimed at embassies of and other targets in Russia and its former Soviet satellites,” Kamlyuk said.

Sergei Karaganov, honorary chairman of the Council on Foreign and Defense Policy, a Moscow-based think tank, said in an interview that such cyber-espionage is increasingly common and that Russia and other countries have attempted to create international protocols to combat it.

“But every time, their attempts have been thwarted by the stiff resistance on the part of the United States, which probably counts too much on its supremacy in this sphere,” he said. “On the other hand, I wouldn’t rule out the possibility of this being an ingenious trick on the part of Kaspersky Lab to boost their trade.”

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Local News

Girl, 11, missing from Lynnwood

Sha’niece Watson’s family is concerned for her safety, according to the sheriff’s office. She has ties to Whidbey Island.

A cyclist crosses the road near the proposed site of a new park, left, at the intersection of Holly Drive and 100th Street SW on Thursday, May 2, 2024, in Everett, Washington. (Ryan Berry / The Herald)
Everett to use $2.2M for Holly neighborhood’s first park

The new park is set to double as a stormwater facility at the southeast corner of Holly Drive and 100th Street SW.

The Grand Avenue Park Bridge elevator after someone set off a fire extinguisher in the elevator last week, damaging the cables and brakes. (Photo provided by the City of Everett)
Grand Avenue Park Bridge vandalized, out of service at least a week

Repairs could cost $5,500 after someone set off a fire extinguisher in the elevator on April 27.

Bruiser, photographed here in November 2021, is Whidbey Island’s lone elk. Over the years he has gained quite the following. Fans were concerned for his welfare Wednesday when a rumor circulated social media about his supposed death. A confirmed sighting of him was made Wednesday evening after the false post. (Jay Londo )
Whidbey Island’s elk-in-residence Bruiser not guilty of rumored assault

Recent rumors of the elk’s alleged aggression have been greatly exaggerated, according to state Fish and Wildlife.

Jamel Alexander stands as the jury enters the courtroom for the second time during his trial at the Snohomish County Courthouse on Monday, May 6, 2024 in Everett, Washington. (Olivia Vanni / The Herald)
Second trial in Everett woman’s stomping death ends in mistrial

Jamel Alexander’s conviction in the 2019 killing of Shawna Brune was overturned on appeal in 2023. Jurors in a second trial were deadlocked.

A car drives past a speed sign along Casino Road alerting drivers they will be crossing into a school zone next to Horizon Elementary on Thursday, March 7, 2024 in Everett, Washington. (Olivia Vanni / The Herald)
Traffic cameras begin dinging school zone violators in Everett

Following a one-month grace period, traffic cameras are now sending out tickets near Horizon Elementary in Everett.

(Photo provided by Washington State Criminal Justice Training Commission, Federal Way Mirror)
Everett officer alleges sexual harassment at state police academy

In a second lawsuit since October, a former cadet alleges her instructor sexually touched her during instruction.

Michael O'Leary/The Herald
Hundreds of Boeing employees get ready to lead the second 787 for delivery to ANA in a procession to begin the employee delivery ceremony in Everett Monday morning.

photo shot Monday September 26, 2011
Boeing faces FAA probe of Dreamliner inspections, records

The probe intensifies scrutiny of the planemaker’s top-selling widebody jet after an Everett whistleblower alleged other issues.

A truck dumps sheet rock onto the floor at Airport Road Recycling & Transfer Station on Thursday, Nov. 30, 2023 in Everett, Washington. (Olivia Vanni / The Herald)
Mountlake Terrace transfer station station closed for most of May

Public Works asked customers to use other county facilities, while staff repaired floors at the southwest station.

Traffic moves along Highway 526 in front of Boeing’s Everett Production Facility on Nov. 28, 2022, in Everett, Washington. (Olivia Vanni / Sound Publishing)
Frank Shrontz, former CEO and chairman of Boeing, dies at 92

Shrontz, who died Friday, was also a member of the ownership group that took over the Seattle Mariners in 1992.

(Kate Erickson / The Herald)
A piece of gum helped solve a 1984 Everett cold case, charges say

Prosecutors charged Mitchell Gaff with aggravated murder Friday. The case went cold after leads went nowhere for four decades.

Boeing firefighters union members and supporters hold an informational picket at Airport Road and Kasch Park Road on Monday, April 29, 2024 in Everett, Washington. (Annie Barker / The Herald)
After bargaining deadline, Boeing locks out firefighters union in Everett

The union is picketing for better pay and staffing. About 40 firefighters work at Boeing’s aircraft assembly plant at Paine Field.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.