Last week, Kaspersky uncovered Red October, a malicious spying campaign that had been monitoring users and governments for five years without being detected. The cybercriminals behind it have begun to retreat, after Kaspersky that they shut down the servers that formed the command and control center (C&C).
Additionally, according to Kaspersky Threatpost, the hosting service providers of the servers and the owners of the domains used in the attacks began shutting down websites and servers.
“It’s clear that they are shutting them down, and right now they have shut them down for good. Not only have the domain name providers shut down the domains and the hosting providers shut down the servers that were the command and control center, but perhaps the attackers themselves have stopped running the entire operation,” said Costin Raiu of Kaspersky Lab.
Over 60 C&C domains have already been revealed, but experts believe these are only “first-level proxies.”
The Red October campaign is one of the most sophisticated cyber espionage campaigns we have ever seen. The section of the report describing the attack spans 140 pages.

