Researchers have discovered a highly advanced malware that they believe was developed by a wealthy nation with the aim of spying on a wide range of international targets in various industries, including healthcare, energy, aviation, and research.
Backdoor Regin, as Symantec researchers named it, bears some resemblance to other Trojans they had discovered and flagged as threats to national security, including Flame, Duqu, and Stuxnet, the worm that was programmed to disrupt Iran's nuclear program.
Regin's programming likely took months or years to complete and contains dozens of sub-branches, which allowed administrators to send the malware to individual targets.
While nearly half of the computers known to have been infected by Regin were at Internet service providers, Symantec believes they were attacked so that the Trojan's administrators could spy on specific Internet service provider customers. Similarly, telecommunications hubs are the second largest category of attacks. It is likely that this medium was chosen so that the attackers could gain access to calls routed through their infrastructure.
Since 2008, the Bacdoor Regin malware.
The malware was active from 2008 until 2011, when its administrators abruptly removed it from infected systems. It reappeared in 2013, and security researchers at Symantec became aware of its release towards the end of that year.

