Mobile Tech Today

CIO Today Network Sites:   Top Tech News  |   CIO Today   |   Mobile Tech Today   |   Data Storage Today
News & Product Reviews for Mobile Tech Users
Riverbed Stingray in AWS
The only full-featured ADC
available for Amazon EC2 today

www.riverbed.com
Sunday, May 19th 
Introducing Simpana® 10 software
Home
Laptops & Tablets
Mobile Phones
Mobile Gadgets
Mobile Apps
BYOD & MDM
iPad
Mobile Industry News
Wireless Connectivity
Wireless Security
GPS & Maps
MTT Press Releases
 
Free Newsletters
Top CIO News
 
Mobile Tech Today
 

Advertisement


Wireless Security

Kaspersky Labs Discovers 'Red October' Malware Spy Ring

Kaspersky Labs Discovers
January 14, 2013 1:55PM

Bookmark and Share
The leading number of Red October infections discovered -- 35 -- is in the Russian Federation, suggesting Red October is not run by the Russian government. In fact, Kaspersky Labs said although Red October is gathering "classified information and geopolitical intelligence," there is "no evidence linking this with a nation-state sponsored attack."

CommVault is a data and information management software company dedicated to providing organizations worldwide with a radically better way to manage data and information. Their unique Solving Forward philosophy allows them to deliver complete solutions with infinite scalability and unprecedented control over data and costs. Be among the first to experience Simpana 10 software. Click here now.

It sounds like a remake of the Tom Clancy novel by the same name, but "Red October" is the name of an advanced cyber espionage network Relevant Products/Services that is targeting governments and other organizations around the world. The network was discovered by the security firm Kaspersky Labs, which announced its findings Monday.

The firm said its researchers have spent several months analyzing malware from the organization, which, since at least 2007, targets organizations primarily in central Asia and in Eastern European countries that were formerly in the Soviet Union, as well as ones in Western Europe and North America.

Hiding the 'True Mothership'

Kaspersky said the attackers have conducted these operations for at least five years, and stolen data Relevant Products/Services, such as security credentials, are reused in later attacks. More than five dozen domain names have been created to control the network of infected machines, utilizing hosting locations in Germany, Russia and other countries.

Targets have included embassies and other diplomatic and governmental locations, research institutions, trade and commerce organizations, nuclear and energy research, oil and gas companies, aerospace and military. Hundreds of infections have been located worldwide.

The firm said that the actual command-and-control infrastructure Relevant Products/Services is a chain of proxy servers that hide the location of the "true mothership command and control server." The network is designed to allow an attacker to recover access to infected machines through other communication channels, if need be. A "resurrection" function enables a malware module to be reinstalled, even if it's been removed.

Red October, which is also called Rocra for short, is designed to steal data from mobile Relevant Products/Services devices, enterprise Relevant Products/Services network equipment, already-deleted files recovered from removable disk drives, e-mail databases from Outlook or POP/IMAP servers, or local FTP servers, in addition to workstations.

'Russian-Speaking Origins'

The observed attacks exploited vulnerabilities in Excel or Word, and, against Tibetan activists and Asia-based military and energy targets, used spear-phishing attacks. Spear phishing is fraudulent e-mail that appears to originate from someone within an organization, and attempts to trick the recipient into revealing confidential data or clicking on a link.

Because of registration data in the command-and-control servers and clues left in executables, Kaspersky, whose world headquarters are in Moscow, said it "strongly" believes the attackers "have Russian-speaking origins." The network was dubbed Red October by Kaspersky because of the use of the Russian language in the code.

Interestingly, the leading number of infections discovered -- 35 -- is in the Russian Federation, suggesting that this operation is not run by the Russian government. In fact, Kaspersky said that there is "no evidence linking this with a nation-state sponsored attack." The main purpose of the attacks appears to be gathering "classified information and geopolitical intelligence," although the use is unknown.

While the malware has been developed by Russian-speaking programmers, the exploits themselves appear to have been handled by Chinese hackers.

The company said it first investigated the Rocra attacks in October of last year at the request of an unnamed "partner," who chooses to remain anonymous. Kaspersky regularly unveils its investigations into major malware attacks, including the Flame virus that apparently attacked computers in Iran. There is no apparent connection between Flame and Red October, the security firm said.

Tell Us What You Think
Comment:

Name:

Advertisement



 Wireless Security
1. Cyberattacks Could Help Syrian Raids
2. Google Glass Raises Privacy Concerns
3. Pentagon Gives iOS 6 Security OK
4. Hackers Find Smartphones Useful
5. Investors Funding Cyberwarfare


advertisement


 Most Popular Articles
1. Half of Companies To Mandate BYOD by 2017, Gartner Says
2. Best of Interop Award Winners Announced
3. Thorsten Heins Predicts the Demise of Tablets
4. Novell Filr Offers IT-Friendly Dropbox Alternative
5. Nokia Takes on BlackBerry with WhatsApp-Focused Asha

Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  Cyberattacks Could Help Syrian Raids
  What's in Store for Apple's iOS 7?
  Windows 8.1: No Cost, Big Pressure
  Soundbars Up the Ante on TV Sound
  Google Glass Raises Privacy Concerns

 Technology Marketplace

BYOD & MDM
Build a business case for a BYOD program.
 
CRM Systems
Free Download: Understanding the Voice of the Customer
 
Cloud & Virtualization
Brocade technologies help enable the full benefits of virtualization.
Riverbed Stingray Traffic Manager on Amazon Web Services
 
Contact Centers
Unlock the potential in your people with Microsoft Dynamics
 
Customer Data
Free Download: Understanding the Voice of the Customer
 
Customer Service
Unlock the potential in your people with Microsoft Dynamics
 
Data Security
Simpana® 10 software: an exponential leap forward
 
Data Storage
Brocade makes it easier to deploy, manage, and scale networks.
 
Enterprise Software
Simpana® 10 software: an exponential leap forward
 
Hardware
Rugged and reliable Panasonic Toughbook® mobile computers.
 
Laptops & Tablets
Rugged and reliable Panasonic Toughbook® mobile computers.
 
Mobile Apps
Build great mobile apps that drive engagement.
 
Mobile Gadgets
Rugged and reliable Panasonic Toughbook® mobile computers.
 
Network Security
Brocade makes it easier to deploy, manage, and scale networks.
 
Mobile Enterprise Spotlight

What's in Store for Apple's iOS 7?
There's been talk recently that Apple's products are beginning to coast on their glorious past. So, with Apple's big Worldwide Developers Conference opening next month, speculation is heating up.

Google Glass Raises Congressional Privacy Concerns
The buzz around Google Glass continues, but it's not all good. Some in Congress have questions. "We are curious whether this new technology could infringe on the privacy of average Americans," their letter to Google says.

Windows Phone Now No. 3 in Market, BlackBerry No. 4
Has Microsoft Phone moved into a coveted though distant third place for smartphone platforms behind Google's Android and Apple's iOS? A new report says yes, while BlackBerry has slipped to No. 4.

Advertisement
Enterprise Software Spotlight

Should Enterprises Skip Over Windows 8?
Because of the interface changes and compatibility issues, most businesses will not adopt Windows 8 as their standard, but must be prepared to meet employee BYOD demand for it, Forrester Research says.

HP and SAP Team To Advance HANA Database Technology
The two tech leaders are working on a system that SAP says could fundamentally change the database market. HANA is SAP's technology that keeps data in-memory, for super fast processing.

Revlon Saving Millions with Microsoft Dynamics
The cosmetics giant is reporting millions of dollars in savings thanks to consolidating its enterprise resource planning by using Microsoft Dynamics ERP. Revlon CIO David Giambruno recently shared his story.

Advertisement
Enterprise Hardware Spotlight

U.S. Defense Department Gives iOS 6 Security OK
In a vote of confidence for Apple's iOS devices, the Defense Department has given the all-clear for employees to use iPads and iPhones for work. But only those running iOS 6, and only if issued by the government.

Cisco Surges After Profit Exceeds Analysts' Estimates
Networking equipment giant Cisco's net income jumped 14 percent in the latest quarter as revenue at all four of its divisions rose for the first time in a year and a half, as tech spending increases.

HP and SAP Team To Advance HANA Database Technology
The two tech leaders are working on a system that SAP says could fundamentally change the database market. HANA is SAP's technology that keeps data in-memory, for super fast processing.

Advertisement
Navigation
Mobile Tech Today
Home/Top News | Laptops & Tablets | Mobile Phones | Mobile Gadgets | Mobile Apps | BYOD & MDM | iPad
Mobile Industry News | Wireless Connectivity | Wireless Security | GPS & Maps | MTT Press Releases
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Mobile Tech Today | Data Storage Today

Services:
FreeNewsFeed | Free Newsletters | XML/RSS Feed

About CIO Today Network | How To Contact Us | Article Reprints | Services for PR Pros (In partnership with NewsFactor) | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2013 Mobile Tech Today. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.