Skip to content
Surf Wiki
Save to docs
geography/russia

From Surf Wiki (app.surf) — the open knowledge base

Red October (malware)

Cyberespionage malware


Cyberespionage malware

Operation Red October or Red October was a cyberespionage malware program discovered in October 2012 and uncovered in January 2013 by Russian firm Kaspersky Lab. The malware was reportedly operating worldwide for up to five years prior to discovery, transmitting information ranging from diplomatic secrets to personal information, including from mobile devices. The primary vectors used to install the malware were emails containing attached documents that exploited vulnerabilities in Microsoft Word and Excel. Later, a webpage was found that exploited a known vulnerability in the Java browser plugin. Red October was termed an advanced cyberespionage campaign intended to target diplomatic, governmental and scientific research organizations worldwide.

A map of the extent of the operation was released by the Kaspersky Lab – the "Moscow-based antivirus firm that uncovered the campaign."

After being revealed, domain registrars and hosting companies shut down as many as 60 domains, used by the virus creators to receive information. The attackers, themselves, shut down their end of the operation, as well.

The perpetrator of the operation has not been conclusively determined but it appeared to have been in operation on some level since May 2007 at the latest. According to Kaspersky Lab, Russian slang words were found in the code which would be "generally unknown to non-native Russian speakers." However, the program also appeared to be built on existing exploits developed by Chinese hackers and previously used against Tibetan activists.

CountryGovernmentEmbassy (Diplomatic)MilitaryNuclear / Energy ResearchAerospaceOil & Gas IndustryTrade and CommerceResearch InstitutionsUnknown Victims
United StatesNoYesNoNoNoNoNoNoNo
RussiaNoYesYesYesNoNoNoYesNo
BelarusYesYesYesYesNoYesNoYesNo
KazakhstanYesYesYesYesYesNoNoNoNo
United Arab EmiratesYesYesNoYesNoYesNoNoNo
AzerbaijanNoYesNoYesNoYesNoYesNo
TurkmenistanYesNoNoYesNoYesNoNoNo
AfghanistanYesYesYesNoNoNoNoNoNo
MoldovaYesYesYesNoNoNoNoNoNo
FranceNoYesYesNoNoNoNoNoNo
SpainYesYesNoNoNoNoNoNoNo
ArmeniaYesYesNoNoNoNoNoNoNo
CyprusYesYesNoNoNoNoNoNoNo
IraqYesNoNoNoNoNoNoNoNo
BruneiYesNoNoNoNoNoNoNoNo
LuxembourgYesNoNoNoNoNoNoNoNo
IndiaNoYesNoNoNoNoNoNoNo
UgandaNoYesNoNoNoNoNoNoNo
PakistanNoYesNoNoNoNoNoNoNo
OmanNoYesNoNoNoNoNoNoNo
Saudi ArabiaNoYesNoNoNoNoNoNoNo
ItalyNoYesNoNoNoNoNoNoNo
PortugalNoYesNoNoNoNoNoNoNo
MoroccoNoYesNoNoNoNoNoNoNo
IsraelNoYesNoNoNoNoNoNoNo
JordanNoYesNoNoNoNoNoNoNo
GreeceNoYesNoNoNoNoNoNoNo
IrelandNoYesNoNoNoNoNoNoNo
BelgiumNoYesNoNoNoNoNoNoNo
GermanyNoYesNoNoNoNoNoNoNo
HungaryNoYesNoNoNoNoNoNoNo
MauritaniaNoYesNoNoNoNoNoNoNo
CongoNoYesNoNoNoNoNoNoNo
South AfricaNoYesNoNoNoNoNoNoNo
BotswanaNoYesNoNoNoNoNoNoNo
MozambiqueNoYesNoNoNoNoNoNoNo
TanzaniaNoYesNoNoNoNoNoNoNo
KenyaNoYesNoNoNoNoNoNoNo
LithuaniaNoYesNoNoNoNoNoNoNo
LatviaNoYesNoNoNoNoNoNoNo
TurkeyNoYesNoNoNoNoNoNoNo
IranNoYesNoNoNoNoNoNoNo
UzbekistanNoYesNoNoNoNoNoNoNo
KuwaitNoYesNoNoNoNoNoNoNo
SwitzerlandNoYesNoNoNoNoNoNoNo
LebanonNoYesNoNoNoNoNoNoNo
AustriaNoYesNoNoNoNoNoNoNo
Georgia (country)NoYesNoNoNoNoNoNoNo
Bosnia & HerzegovinaNoYesNoNoNoNoNoNoNo
SerbiaNoNoNoNoNoNoNoNoYes
FinlandNoNoNoNoNoNoNoNoYes
Czech RepublicNoNoNoNoNoNoNoNoYes
SlovakiaNoNoNoNoNoNoNoNoYes
MacedoniaNoNoNoNoNoNoNoNoYes
AlbaniaNoNoNoNoNoNoNoNoYes
MaliNoNoNoNoNoNoNoNoYes
AustraliaNoNoNoNoNoNoNoNoYes
ChileNoNoNoNoNoNoNoNoYes
BrazilNoNoNoNoNoNoNoNoYes
EthiopiaNoNoNoNoNoNoNoNoYes
BulgariaNoNoNoNoNoNoNoNoYes
BahrainNoNoNoNoNoNoNoNoYes
SlovakiaNoNoNoNoNoNoNoNoYes

References

References

  1. McAllister, Neil. (16 Jan 2013). "Surprised? Old Java exploit helped spread Red October spyware". [[The Register]].
  2. (3 Mar 2014). "The "Red October" Campaign – An Advanced Cyber Espionage Network Targeting Diplomatic and Government Agencies". [[Kaspersky Lab]].
  3. Goodin, Dan. (15 Jan 2013). "Red October relied on Java exploit to infect PCs". [[Ars Technica]].
  4. (January 14, 2013). "Cybersleuths Uncover 5-Year Spy Operation Targeting Governments, Others".
Info: Wikipedia Source

This article was imported from Wikipedia and is available under the Creative Commons Attribution-ShareAlike 4.0 License. Content has been adapted to SurfDoc format. Original contributors can be found on the article history page.

Want to explore this topic further?

Ask Mako anything about Red October (malware) — get instant answers, deeper analysis, and related topics.

Research with Mako

Free with your Surf account

Content sourced from Wikipedia, available under CC BY-SA 4.0.

This content may have been generated or modified by AI. CloudSurf Software LLC is not responsible for the accuracy, completeness, or reliability of AI-generated content. Always verify important information from primary sources.

Report