YOUR FRIENDS' ACTIVITY

    The Week

    Operation Red October: The top-secret global espionage campaign that's been running for five years

    A rogue group is covertly collecting top-secret data with an infrastructure rivaling Flame and Stuxnet

    Russian antivirus firm Kaspersky Labs has uncovered a high-level cyber-espionage campaign that has been targeting government agencies, research institutions, and diplomats for the past five years to gather "classified information and geopolitical intelligence," per a report published on Monday. Here's what we know about operation "Red October," which has some hallmarks of government-sponsored C++ computer viruses Flame and Stuxnet that came before it

    What's going on exactly?
    A sophisticated digital infrastructure that's utilizing a chain of more than 60 command-and-control servers is silently gathering data from high-profile targets around the world, and avoiding detection. Whoever is behind the operation has been compiling troves of top-secret documents and files from computers, smartphones, and external storage hardware like USB sticks since 2007. Kasperksy says the campaign is still active, with a complexity that rivals the Flame virus allegedly used by the U.S. and Israel to spy on Iran's nuclear efforts.

    Who's being targeted?
    Most of the targets are in Eastern Europe and Central Asia, but more than 60 countries have been hit; accounts have been compromised in the U.S., Australia, Ireland, Switzerland, Japan, Spain, and more. Kaspersky declined to disclose the identities of the targets, but Kim Zetter at Wired notes that the agencies and institutions involved relate to "nuclear and energy research and companies in the oil and gas and aerospace industries." 

    How does the attack work?
    The Red October worm first infiltrates computers using email attachments — things like Word and Excel files. Once a computer is infected, that data is beamed back to a still-invisible command server mothership, which assigns each victim's computer a 20-hex digit code to identify it. This foothold, more alarmingly, can spread to mobile devices like smartphones, or even entire enterprise networks like Cisco to steal account information and passwords from databases. They also help hackers reinfect machines in case the malware is removed by antivirus scanners. The techniques and code likely have Chinese origins, and have been used in previous attacks targeting Tibetan activists and military in Asia. (Click here for a detailed walkthrough of how the attack works.)

    Who's behind it?
    Unlike Flame and Stuxnet, Red October probably isn't a government-sponsored enterprise. Rather, Kasperspy says the cybercriminals behind this worm are most likely based in Russia, and are looking to sell their intelligence for a premium on the black market to governments and others willing to pay. 

    What kind of information are they gathering?
    They're taking everything: .pdf files, Excel spreadsheets, and documents with .acid extensions, which are run through Acid Cryptofiler, an encryption program used by the French military and NATO. The virus "can also scrub enterprise network equipment and removable disk drives, copy entire email databases from Outlook storage and POP/IMAP servers, and it can even take deleted files off USB sticks using its own recovery mechanism," says Eric Limer at Gizmodo. "Red October doesn't mess around."

    What's being done to stop it?
    The investigation is still ongoing. Per the report published Monday: "Kaspersky Lab, in collaboration with international organizations, Law Enforcement, Computer Emergency Response Teams (CERTs) and other IT security companies is continuing its investigation of Operation Red October by providing technical expertise and resources for remediation and mitigation procedures."

    SEE MORE: Obama's war on hackers: 5 things you need to know

    View this article on TheWeek.com Get 4 Free Issues of The Week

    Other stories from this topic:

    Like on Facebook - Follow on Twitter - Sign-up for Daily Newsletter
    Loading...

    More Politics News

    • Boyfriend espaces out window as husband confronts cheating wife [VIDEO]

      As part of perhaps the most spectacular walk-of-shame ever, an underwear-clad lover escaped from a third floor bedroom as the returning husband confronted his cheating wife on a balcony.

    • Why We Can't Forget That Oklahoma's Senators Voted Against Sandy Relief

      Nearly four months ago, Oklahoma Senators Tom Coburn and James Inhofe both voted against H.R.152, the Disaster Relief Appropriations Act that eventually sent $50.5 billion in relief to victims of Hurricane Sandy. And in the flurry of last night's devastation in Moore, Oklahoma. it was impossible not to forget that fact, knowing the federal government would soon rally to the cause.

    • Cycling-Road-Giro d'Italia classification after stage 16

      May 21 (Infostrada Sports) - Classification from Giro d'Italia after Stage 16 on Tuesday 1. Vincenzo Nibali (Italy / Astana) 67:55:36" 2. Cadel Evans (Australia / BMC Racing) +1:26" 3. Rigoberto Uran (Colombia / Team Sky) +2:46" 4. Michele Scarponi (Italy / Lampre) +3:53" 5. Przemyslaw Niemiec (Poland / Lampre) +4:13" 6. Mauro Santambrogio (Italy / Vini Fantini) +4:57" 7. Carlos Betancur (Colombia / AG2R) +5:15" 8. Rafal Majka (Poland / Saxo - Tinkoff) +5:20" 9. Benat Intxausti (Spain / Movistar) +5:47" 10. Domenico Pozzovivo (Italy / AG2R) +7:34" 11. Tanel Kangert (Estonia / Astana) +7:43" ...

    • Woman on Trump: 'Somebody had to stand up to him'

      An 87-year-old woman who alleges Donald Trump cheated her in a skyscraper-condo sale told jurors Monday she had qualms about suing the real estate mogul and TV celebrity. But, she quickly added, "Somebody ...

    • Afghan students protest women's rights decree

      KABUL, Afghanistan (AP) — Hard-line Islamist students protested Wednesday in the Afghan capital demanding the repeal of a presidential decree for women's rights that they say is un-Islamic. It was the latest sign of a backlash against the legal protections passed in the 12 years since the toppling of the Taliban regime known for its harsh treatment of women.

    • Teens Are Turning Away from Facebook Because Tumblr Is Real, and Parent-Free

      Teenagers really are over Facebook. In February the social network warned investors that "our younger users ... are aware of and actively engaging with other products and services similar to, or as a substitute for, Facebook." And in April the investment bank Piper Jaffray reported that products and services like Tumblr and Twitter were further eroding Facebook's dominance among the Justin Bieber set. But why? In a deep report published on Tuesday, Pew Research explains that teenagers departing the social network's blue confines are looking for something more... real. ...

    • Gender Reassignment Involves More Than A Lifestyle Change

      DEAR ABBY: My husband and I recently learned that our sister-in-law's adult son from a prior marriage, "Charlie," is now "Claire." My husband and I have three sons, ages 2 to 10 years.This sister-in-law expressed concern that our 10-year-old would remember Charlie and say something inappropriate. She's demanding that we lie to him and tell him Claire is another daughter we have never met.My husband and I do not lie to our children. We feel it is best to explain to all three of our sons that Charlie has decided to make a lifestyle change and let them ask questions if they choose. ...

    Loading...

    Follow Yahoo! News