Russian lab reports major malware discovery

MOSCOW — In what is being called a new hunt for Red October, a Russian cyber-security company says it has found a major international malware system that has attacked and compromised the computers of government agencies, diplomatic consulates, research centers and defense installations, among other sensitive institutions.

The malware has siphoned off terabytes’ worth of information, much of it classified, researchers with Moscow-based Kaspersky Lab said in a report this week. The origin of the program and the motives of the attackers remain elusive, but there are hints that the programmers are Russian, the report says.

“Last October we first received from our clients samples of something we soon gathered was not just a malware program but a multi-component attack platform, initially targeting embassies around the world,” Vitaly Kamlyuk, a senior anti-virus expert at Kaspersky, said Wednesday. “We called the virus ‘Red October’ because we detected it in October and because it required a level of red-alert attention to tackle.”

Similar to the Flame virus, a now-defunct spyware program Kaspersky thwarted last year, the new virus usually infiltrates computers through an email attachment camouflaged to mimic ordinary business correspondence, the expert said.

“One embassy was looking to buy a car and received the virus in a car sale proposal they soon found in their inbox,” Kamlyuk said.

Kaspersky, a leading developer of commercial anti-virus software, said it found victims of the malware with IP addresses in 39 countries, led by Switzerland, Kazakhstan and Greece. The most common targets included embassies, government agencies and research institutes, as well as aerospace and energy companies.

Kaspersky said the malware was probably being operated by a government or criminal organization large enough to employ at least two dozen highly trained programmers.

Independent experts in the United States offered differing views on who might be responsible.

“The two primary suspects for this operation would have been either Russia or China, just based on some of the data,” said John Bumgarner, research director for the U.S. Cyber Consequences Unit, a nongovernmental think tank.

But researcher Jeffrey Carr, author of “Inside Cyber Warfare,” theorized that the malware was the work of the foreign intelligence service of a NATO or European Union country, and that the intent was to spy on Russian embassies.

“It’s a pretty good guess” that Russia’s spy service, the FSB, approached Kaspersky and asked the firm to investigate, Carr said. “One of the indications was that they were specifically looking for Russian documents.”

Kaspersky researchers said the spyware, when first installed, might be only several hundred kilobytes in size, minuscule by modern computer standards. But as it gets established and communicates with its controllers, it may grow to several megabytes.

The virus records the names of the users, their IP addresses, information stored on their processors and local disks, the history of browsers, logins and passwords, and the records of devices plugged into USB ports, including smartphones, according to the report.

Like the Flame program, the new virus can record screen shots, as well as keystrokes.

Evidence of the Red October virus dates to May 2007, Kamlyuk said. The program was embedded in Microsoft Excel and Word documents that had been used by Chinese hackers against Asian companies and Tibetan political activists, Kamlyuk said.

“But soon enough,” he said, “we realized that, despite its obvious Chinese roots and the fact that no agencies in China were in fact targets of the new malicious program, the Chinese hackers had nothing to do with Red October.”

The language used in the malware was primarily English, but not that of a native English speaker. It included Cyrillic symbols and transliterations of terms from Russian computer jargon, the researchers said.

For instance, Kamlyuk said, the malware sometimes uses the Russian word “zakladka” for “bookmark” or “marker” and “proga” for “programs.”

“Many domain names of the malware were registered under fake Russian names and addresses too,” he said.

“Now we have come to the realization that we are dealing with something programmed by Russian-speaking experts, based on Chinese hackers’ exploit documents and mostly aimed at embassies of and other targets in Russia and its former Soviet satellites,” Kamlyuk said.

Sergei Karaganov, honorary chairman of the Council on Foreign and Defense Policy, a Moscow-based think tank, said in an interview that such cyber-espionage is increasingly common and that Russia and other countries have attempted to create international protocols to combat it.

“But every time, their attempts have been thwarted by the stiff resistance on the part of the United States, which probably counts too much on its supremacy in this sphere,” he said. “On the other hand, I wouldn’t rule out the possibility of this being an ingenious trick on the part of Kaspersky Lab to boost their trade.”

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Local News

Alan Edward Dean, convicted of the 1993 murder of Melissa Lee, professes his innocence in the courtroom during his sentencing Wednesday, April 24, 2024, at Snohomish County Superior Court in Everett, Washington. (Ryan Berry / The Herald)
Bothell man gets 26 years in cold case murder of Melissa Lee, 15

“I’m innocent, not guilty. … They planted that DNA. I’ve been framed,” said Alan Edward Dean, as he was sentenced for the 1993 murder.

Bothell
Man gets 75 years for terrorizing exes in Bothell, Mukilteo

In 2021, Joseph Sims broke into his ex-girlfriend’s home in Bothell and assaulted her. He went on a crime spree from there.

A Tesla electric vehicle is seen at a Tesla electric vehicle charging station at Willow Festival shopping plaza parking lot in Northbrook, Ill., Saturday, Dec. 3, 2022. A Tesla driver who had set his car on Autopilot was “distracted” by his phone before reportedly hitting and killing a motorcyclist Friday on Highway 522, according to a new police report. (AP Photo/Nam Y. Huh)
Tesla driver on Autopilot caused fatal Highway 522 crash, police say

The driver was reportedly on his phone with his Tesla on Autopilot on Friday when he crashed into Jeffrey Nissen, killing him.

Boeing firefighters union members and supporters hold an informational picket at Airport Road and Kasch Park Road on Monday, April 29, 2024 in Everett, Washington. (Annie Barker / The Herald)
After bargaining deadline, Boeing locks out firefighters union in Everett

The union is picketing for better pay and staffing. About 40 firefighters work at Boeing’s aircraft assembly plant at Paine Field.

Andy Gibbs, co-owner of Andy’s Fish House, outside of his restaurant on Wednesday, May 1, 2024 in Snohomish, Washington. (Olivia Vanni / The Herald)
City: Campaign can’t save big tent at Andy’s Fish House in Snohomish

A petition raised over 6,000 signatures to keep the outdoor dining cover — a lifeline during COVID. But the city said its hands are tied.

A Tesla electric vehicle is seen at a Tesla electric vehicle charging station at Willow Festival shopping plaza parking lot in Northbrook, Ill., Saturday, Dec. 3, 2022. A Tesla driver who had set his car on Autopilot was “distracted” by his phone before reportedly hitting and killing a motorcyclist Friday on Highway 522, according to a new police report. (AP Photo/Nam Y. Huh)
After Stanwood man’s death, feds open probe into Tesla Autopilot feature

The National Highway Traffic Safety Administration was investigating Tesla’s recall on its vehicles with the Autopilot function.

Dorothy Crossman rides up on her bike to turn in her ballot  on Tuesday, Aug. 1, 2023 in Everett, Washington. (Olivia Vanni / The Herald)
Repeat and hopeful politicians can file for elections this week

Do you think you have what it takes to serve in the Legislature? This week, you can sign up to run.

Pacific Stone Company owner Tim Gray talks with relocation agent Dan Frink under the iconic Pacific Stone sign on Friday, May 3, 2024, in Everett, Washington. The business will be relocating to Nassau Street near the intersection of Marine View Drive and California Street. (Ryan Berry / The Herald)
Will readerboard romance on Rucker survive long-distance relationship?

Pacific Stone is moving a mile from Totem Diner, its squeeze with another landmark sign. Senior housing will be built on the site.

The site of a new Uniqlo store coming to Alderwood Mall in Lynnwood, Washington on May, 3, 2024. (Annie Barker / The Herald)
Clothing retailer Uniqlo to open Lynnwood store

Uniqlo, a Tokyo-based chain, offers clothing for men, women and children. The company plans to open 20 new stores this year in North America.

A dog looks up at its trainer for the next command during a training exercise at a weekly meeting of the Summit Assistance Dogs program at the Monroe Correctional Complex on Tuesday, Feb. 6, 2024 in Monroe, Washington. (Olivia Vanni / The Herald)
At Monroe prison, dog training reshapes lives of humans, canines alike

Since 2010, prisoners have helped train service animals for the outside world. “I don’t think about much else,” one student said.

James McNeal. Courtesy photo
Charges: Ex-Bothell council member had breakup ‘tantrum’ before killing

James McNeal was giving Liliya Guyvoronsky, 20, about $10,000 per month, charging papers say. King County prosecutors charged him with murder Friday.

Edmonds City Council members answer questions during an Edmonds City Council Town Hall on Thursday, April 18, 2024 in Edmonds, Washington. (Olivia Vanni / The Herald)
Edmonds wants to hear your thoughts on future of fire services

Residents can comment virtually or in person during an Edmonds City Council public hearing set for 7 p.m. Tuesday.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.