Kaspersky an extensive report detailing a sophisticated espionage campaign by a malware that has been running since May 2007. The espionage operation targets “several hundred” governments and diplomatic organizations, primarily in Eastern Europe (mainly the former USSR republics) and Central Asia, but also in Western Europe and North America.
Among the victims were embassies, consulates, shopping malls, nuclear research centers, as well as oil and gas organizations. The vast majority of infected computers were found in Russia (Kaspersky detected 35), followed by Kazakhstan with 21 cases, Azerbaijan with 15, Belgium with 15, and India with 14. Six infected machines were found in the United States.
“During our research, we have discovered over 1,000 unique files, belonging to about 30 different module categories,” Kaspersky’s report states. “The attackers managed to stay in the game for over five years without being noticed by anyone, as they managed to evade detection by most antivirus products, while the files they have taken must be hundreds of terabytes by now.”
The malware used by the attackers is extremely flexible and customized for each victim. The victim had a unique identifier, so they received a different module tailored just for them. Each module is designed to perform different tasks, but its ultimate goal was to steal a variety of files, including PDF files, Excel spreadsheets, CSV files, and ACID files. The latter files seem to be the key: the attackers with the malware were trying to steal files encrypted with Acid Cryptofiler, an encryption program developed by the French military and now used by many countries in the European Union and NATO to encrypt classified information.
The malware not only steals files (including those that have already been deleted), but also grabs emails, password files, copies everything the victim types, takes screenshots, and steals browsing history from Chrome, Firefox, Internet Explorer, Opera, etc. The main goal is to gather as many sensitive documents as possible, and it does everything it can to achieve this. In fact, the malicious modules disguise themselves as Microsoft Office and Adobe Reader plugins and help attackers re-infect a computer once the first threat is detected and removed by an antivirus scanner.
The threat also grabs contacts, call history, calendars, text messages, and browsing history from smartphones, such as iPhones, Android mobiles, as well as Windows Mobile devices (especially from manufacturers Nokia, Sony Ericsson, and HTC).
Kaspersky said, as reported by TNW, that the attackers are using over 60 domains and several servers (mainly from Germany, Russia, and Austria) to manage the network of infected computers. However, the command and control (C&C) servers are located behind a three-layer proxy chain to hide the location of the “mother” malicious computer and prevent researchers from finding the final collection point, where all the stolen documents, keystrokes, screenshots, and are processed:
The security company said it believes the perpetrators are Russian but that there is also a possibility that the entire operation is state-backed.
Researchers discovered several Russian words embedded in the malware code. For example, the word “zakladka,” which can mean “bookmark” in Russian (and Polish), but could also be a Russian slang term meaning “undeclared functionality” or a “microphone embedded in a brick of the embassy building,” appears several times. The word “proga,” another common Russian word meaning program or application, was frequently used.
The company named the new malicious campaign “Operation Red October” after the Russian submarine featured in the Tom Clancy novel.


