The Edmond Sun

Nation & World

January 17, 2013

Russia’s Kaspersky Lab reports major malware discovery

MOSCOW — In what is being called a new hunt for Red October, a Russian cyber-security company says it has discovered a major international malware system that has attacked and compromised the computers of government agencies, diplomatic consulates, research centers and defense installations, among other sensitive institutions.

The malware has siphoned off terabytes’ worth of information, much of it classified, researchers with Moscow-based Kaspersky Lab said in a report this week. The origin of the program and the motives of the attackers remain elusive, but there are hints that the programmers are Russian, the report says.

“Last October we first received from our clients samples of something we soon gathered was not just a malware program but a multi-component attack platform, initially targeting embassies around the world,” Vitaly Kamlyuk, a senior anti-virus expert at Kaspersky, said in an interview Wednesday. “We called the virus ‘Red October’ because we detected it in October and because it required a level of red-alert attention to tackle.”

Similar to the Flame virus, a now-defunct spyware program Kaspersky thwarted last year, the new virus usually infiltrates computers through an email attachment camouflaged to mimic ordinary business correspondence, the expert said.

“One embassy was looking to buy a car and received the virus in a car sale proposal they soon found in their inbox,” Kamlyuk said.

Kaspersky, a leading developer of commercial anti-virus software, said it found victims of the malware with IP addresses in 39 countries, led by Switzerland, Kazakhstan and Greece. The most common targets included embassies, government agencies and research institutes, as well as aerospace and energy companies.

Kaspersky said the malware was probably being operated by a government or criminal organization large enough to employ at least two dozen highly trained programmers.

Independent experts in the United States offered differing views on who might be responsible.

“The two primary suspects for this operation would have been either Russia or China, just based on some of the data,” said John Bumgarner, research director for the U.S. Cyber Consequences Unit, a nongovernmental think tank.

But researcher Jeffrey Carr, author of “Inside Cyber Warfare,” theorized that the malware was the work of the foreign intelligence service of a NATO or European Union country, and that the intent was to spy on Russian embassies.

“It’s a pretty good guess” that Russia’s spy service, the FSB, approached Kaspersky and asked the firm to investigate, Carr said. “One of the indications was that they were specifically looking for Russian documents.”

Kaspersky researchers said the spyware, when first installed, might be only several hundred kilobytes in size, minuscule by modern computer standards. But as it gets established and communicates with its controllers, it may grow to several megabytes.

The virus records the names of the users, their IP addresses, information stored on their processors and local disks, the history of browsers, logins and passwords, and the records of devices plugged into USB ports, including smartphones, according to the report.

Like the Flame program, the new virus can record screen shots, as well as keystrokes.

Evidence of the Red October virus dates to May 2007, Kamlyuk said. The program was embedded in Microsoft Excel and Word documents that had been used by Chinese hackers against Asian companies and Tibetan political activists, Kamlyuk said.

"But soon enough,” he said, “we realized that, despite its obvious Chinese roots and the fact that no agencies in China were in fact targets of the new malicious program, the Chinese hackers had nothing to do with Red October.”

The language used in the malware was primarily English, but not that of a native English speaker. It included Cyrillic symbols and transliterations of terms from Russian computer jargon, the researchers said.

For instance, Kamlyuk said, the malware sometimes uses the Russian word “zakladka” for “bookmark” or “marker” and “proga” for “programs.”

“Many domain names of the malware were registered under fake Russian names and addresses too,” he said.

“Now we have come to the realization that we are dealing with something programmed by Russian-speaking experts, based on Chinese hackers’ exploit documents and mostly aimed at embassies of and other targets in Russia and its former Soviet satellites,” Kamlyuk said.

Sergei Karaganov, honorary chairman of the Council on Foreign and Defense Policy, a Moscow-based think tank, said in an interview that such cyber-espionage is increasingly common and that Russia and other countries have attempted to create international protocols to combat it.

“But every time, their attempts have been thwarted by the stiff resistance on the part of the United States, which probably counts too much on its supremacy in this sphere,” he said. “On the other hand, I wouldn’t rule out the possibility of this being an ingenious trick on the part of Kaspersky Lab to boost their trade.”

1
Text Only
Nation & World
  • MS_injection well.jpg Agency clarifies earthquake-related misinformation

    A state agency says misinformation related to the debate about the cause of more earthquakes across Central Oklahoma includes oil well types, well numbers and injection pressure.
    The Prague sequence of 2011 along the Wilzetta Fault zone included a significant foreshock, a main shock of magnitude 5.7 and numerous aftershocks. It has been suggested that this sequence represents tremors triggered by fluid injection.
    More recently, earthquakes have been recorded in the vicinity of Jones, Arcadia Lake, Edmond, Guthrie, Langston and Crescent. Regulators and scientists are working together to better understand what’s causing all the shaking.

    April 16, 2014 1 Photo

  • bomb1 VIDEO: A year after marathon bombing, Boston remains strong

    The City of Boston came together Tuesday to honor those who were injured and lost their lives at the Boston Marathon on the one-year anniversary of the bombing. While the day was sure to be emotional, those affected by last year's race are showing they won't let the tragedy keep them down.

    April 16, 2014 1 Photo

  • New study counters pot legalization argument

    A new study raises a strong challenge to the idea that casual marijuana use isn’t associated with bad consequences, a researcher says.
    Researchers say the findings suggest recreational marijuana use may lead to previously unidentified brain changes and highlight the importance of research aimed at understanding the long-term effects of low to moderate marijuana use on the brain.

    April 15, 2014

  • Anita Hill.jpg Anita Hill reflects on her fateful testimony, 23 years later

    Back in 1993, I rounded a corner of a Laguna Beach, Calif., grocery store and walked straight into Anita Hill.
    We both stopped in our tracks. She looked slightly panicked, like someone had turned on a light in a room, and all she wanted was the door.
    It took a moment to register that this was the woman who, just two years before, calmly testified before a Senate committee about the sexual harassment she endured while working for U.S. Supreme Court nominee Clarence Thomas  at the Equal Employment Opportunity Commission, of all places.

    April 15, 2014 1 Photo

  • jc_Erick Wyatt.JPG Norman man takes on challenge to unseat Inhofe

    EDITOR’S NOTE: This is one in a series of candidate profiles leading up to the 2014 Oklahoma elections.

    Erick Wyatt is running for U.S. Senate to be a strong voice of the people, he said. More than anything, Wyatt said he is running against incumbent U.S. Sen. Jim Inhofe for the sake of his children.
    The Norman Republican vows to represent the people’s interests instead of the interests of powerful political groups, Wyatt said.

    April 14, 2014 1 Photo

  • 20140414_MALAYSIA_Bluefin.jpg In new phase to find Flight 370, search robot will enter ocean

    The pings have sputtered out in the multinational search for Malaysia Airlines Flight 370, forcing search crews to deploy an underwater robot to find a plane that’s eluded human efforts.
    In a last-ditch effort to find the Boeing 777 and its black box flight recorders, a U.S. Navy submersible vehicle will be used to scan an area in the southern Indian Ocean for debris.
    “We haven’t had a single detection in six days, so I guess it’s time to go underwater,” Angus Houston, who heads Australia’s Joint Agency Coordination Center, told a news conference in that country’s western city of Perth on Monday.

    April 14, 2014 1 Photo

  • 25801486.jpg VIDEO: Northern California bus crash kills 10

    At least nine people died in Northern California on Thursday night, in an accident involving a bus, a car and FedEx truck. The bus was filled with high school students from Southern California who were on their way to visit a college campus.

    April 11, 2014 1 Photo

  • Strong earthquake rattles Logan County

    Ray Dorwart, owner of Guthrie’s Dorwart Custom Boots, 117 S. Second, said he was in his store working on a sewing machine when he felt the structure shake Monday morning.
    Dorwart was on the phone with an out-of-state friend when he heard some tools rattle and felt the wood floor vibrate.

    April 7, 2014

  • Number of Americans without health insurance reaches new low

    The share of Americans without health insurance has dropped to the lowest level since before President Barack Obama took office, according to a new national survey that provides more evidence the health care law is extending coverage to millions of the previously uninsured.
    Just 14.7 percent of adults lacked coverage in the second half of March, down from 18 percent in the last quarter of 2013, the survey from Gallup found.

    April 7, 2014

  • Daniel Dissinger, 13.jpg Investigators seek cause of fire that killed 3 brothers

    Two siblings, a 14-year-old girl and a 10-year-old boy, survived the early-morning Friday inferno that may have been touched off by kerosene lanterns used in the home. They ran to a neighbor’s house to ask for help and were later treated for smoke inhalation.
    A sixth child, age 4 ½, was spending the night at a friend’s house.

    April 7, 2014 2 Photos