The attackers carrying out the Red October cyber espionage campaign, detailed by security firm Kaspersky yesterday, have already started running scared.
Various embassies and other government bodies, including nuclear and energy organisations, were hit by the Red October group in highly targeted attacks, which started back in 2007.
But the clandestine five-year initiative looks set to fall apart, having been made public yesterday by the Russian security firm. Kaspersky has seen pieces of the cyber espionage campaign’s command & control infrastructure come offline, although it is still showing some signs of life.
“The attackers started dismantling the infrastructure last night at 11pm GMT, by taking down some of the C2s [command servers] and superproxies,” Costin Raiu, senior security researcher at Kaspersky Labs, told TechWeekEurope.
“At the same time, ISPs have shut down some of the C2s while registrars have killed the domain names. Currently, there are still some active servers, however, the infrastructure is severely disrupted and mostly not working anymore.”
Other details about the campaign emerged today. F-Secure posted a number of screenshots of the malicious Microsoft Word and Excel files used by the Red October crew:
“We see thousands of similar documents in our systems every month. The Red October attacks are interesting because of the large scale of the espionage done by a single entity, and the long timespan they cover,” F-Secure said in a blog post. “However, the sad truth is that companies and governments are constantly under similar attacks from many different sources.”
Security company Seculert found the Red October attackers were exploiting an ex-zero-day vulnerability in Java, which Oracle patched back in October 2011.
“Looking at the server side source code of the malware payload page, we can see that the attackers are adding a fingerprint at the end of the malware executable, which includes the unique identifier of the targeted victim. This is the same unique identifier which is used by the malware later on while communicating with the C2 servers,” a blog from Seculert read.
Interested by tech and fascinating plots? Try our tech in the movies quiz!
Fourth quarter results beat Wall Street expectations, as overall sales rise 6 percent, but EU…
Hate speech non-profit that defeated Elon Musk's lawsuit, warns X's Community Notes is failing to…
Good luck. Russia demands Google pay a fine worth more than the world's total GDP,…
Google Cloud signs up Spotify, Paramount Global as early customers of its first ARM-based cloud…
Facebook parent Meta warns of 'significant acceleration' in expenditures on AI infrastructure as revenue, profits…
Microsoft says Azure cloud revenues up 33 percent for September quarter as capital expenditures surge…