<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://en.bharatpedia.org/w/index.php?action=history&amp;feed=atom&amp;title=Regin_%28malware%29</id>
	<title>Regin (malware) - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://en.bharatpedia.org/w/index.php?action=history&amp;feed=atom&amp;title=Regin_%28malware%29"/>
	<link rel="alternate" type="text/html" href="https://en.bharatpedia.org/w/index.php?title=Regin_(malware)&amp;action=history"/>
	<updated>2026-08-20T21:06:22Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.6</generator>
	<entry>
		<id>https://en.bharatpedia.org/w/index.php?title=Regin_(malware)&amp;diff=430218&amp;oldid=prev</id>
		<title>Ajay Kumar: Created a new article</title>
		<link rel="alternate" type="text/html" href="https://en.bharatpedia.org/w/index.php?title=Regin_(malware)&amp;diff=430218&amp;oldid=prev"/>
		<updated>2023-09-25T18:45:46Z</updated>

		<summary type="html">&lt;p&gt;Created a new article&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Short description|Sophisticated malware}}&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Regin&amp;#039;&amp;#039;&amp;#039; (also known as &amp;#039;&amp;#039;&amp;#039;Prax&amp;#039;&amp;#039;&amp;#039; or &amp;#039;&amp;#039;&amp;#039;QWERTY&amp;#039;&amp;#039;&amp;#039;) is a sophisticated [[malware]] and [[computer hacking|hacking]] toolkit used by United States&amp;#039; [[National Security Agency]] (NSA) and its British counterpart, the [[Government Communications Headquarters]] (GCHQ).&amp;lt;ref name=nsa-und-gchq/&amp;gt;&amp;lt;ref&amp;gt;{{cite news |title=Experts Unmask &amp;#039;Regin&amp;#039; Trojan as NSA Tool |url=http://www.spiegel.de/international/world/regin-malware-unmasked-as-nsa-tool-after-spiegel-publishes-source-code-a-1015255.html |access-date=9 November 2021 |work=Spiegel.de}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{Cite magazine|last=Zetter|first=Kim|title=Researchers Uncover Government Spy Tool Used to Hack Telecoms and Belgian Cryptographer|language=en-US|magazine=Wired|url=https://www.wired.com/2014/11/mysteries-of-the-malware-regin/|access-date=2022-02-22|issn=1059-1028}}&amp;lt;/ref&amp;gt; It was first publicly revealed by [[Kaspersky Lab]], [[NortonLifeLock|Symantec]], and [[The Intercept]] in November 2014.&amp;lt;ref name=&amp;quot;news&amp;quot;&amp;gt;{{cite web|url=http://securelist.com/blog/research/67741/regin-nation-state-ownage-of-gsm-networks|title=Regin Revealed|publisher=Kaspersky Lab|access-date=24 November 2014}}&amp;lt;/ref&amp;gt;&amp;lt;ref name=&amp;quot;intercept20041124&amp;quot;/&amp;gt; The malware targets specific users of [[Microsoft Windows]]-based computers and has been linked to the US intelligence-gathering agency [[NSA]] and its British counterpart, the [[GCHQ]].&amp;lt;ref&amp;gt;{{Cite web|url=https://arstechnica.com/tech-policy/2015/10/top-german-official-infected-by-highly-advanced-spy-trojan-with-nsa-ties/|title = Top German official infected by highly advanced spy trojan with NSA ties|date = 26 October 2015}}&amp;lt;/ref&amp;gt;&amp;lt;ref name=&amp;quot;NYT-20141124-NP&amp;quot;&amp;gt;{{cite news |last=Perlroth |first=Nicole |title=Symantec Discovers &amp;#039;Regin&amp;#039; Spy Code Lurking on Computer Networks |url=http://bits.blogs.nytimes.com/2014/11/24/symantec-discovers-spy-code-lurking-on-computer-networks/ |date=24 November 2014 |work=[[New York Times]] |access-date=25 November 2014 }}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=https://firstlook.org/theintercept/2014/12/13/belgacom-hack-gchq-inside-story/|title=The Inside Story of How British Spies Hacked Belgium&amp;#039;s Largest Telco|publisher=The Intercept|first=Ryan|last=Gallagher|date=13 December 2014}}&amp;lt;/ref&amp;gt; &amp;#039;&amp;#039;The Intercept&amp;#039;&amp;#039; provided samples of Regin for download, including malware discovered at a Belgian telecommunications provider, [[Belgacom]].&amp;lt;ref name=&amp;quot;intercept20041124&amp;quot;/&amp;gt; Kaspersky Lab says it first became aware of Regin in spring 2012, but some of the earliest samples date from 2003.&amp;lt;ref&amp;gt;[http://www.kaspersky.com/about/news/virus/2014/Regin-a-malicious-platform-capable-of-spying-on-GSM-networks Kaspersky:Regin: a malicious platform capable of spying on GSM networks], 24 November 2014&amp;lt;/ref&amp;gt; (The name Regin is first found on the [[VirusTotal]] website on 9 March 2011.&amp;lt;ref name=intercept20041124/&amp;gt;) Among computers infected worldwide by Regin, 28 percent were in [[Russia]], 24 percent in [[Saudi Arabia]], 9 percent each in [[Mexico]] and [[Ireland]], and 5 percent in each of [[India]], [[Afghanistan]], [[Iran]], [[Belgium]], [[Austria]], and [[Pakistan]].&amp;lt;ref name=&amp;quot;symantecblog&amp;quot;&amp;gt;{{cite web|url=http://www.symantec.com/connect/blogs/regin-top-tier-espionage-tool-enables-stealthy-surveillance|title=Regin: Top-tier espionage tool enables stealthy surveillance|publisher=Symantec|access-date=25 November 2014|date=23 November 2014}}&amp;lt;/ref&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Kaspersky Lab|Kaspersky]] has said the malware&amp;#039;s main victims are private individuals, small businesses and [[Telecommunications service provider|telecom companies]]. Regin has been compared to [[Stuxnet]] and is thought to have been developed by &amp;quot;well-resourced teams of developers&amp;quot;, possibly a [[Western culture|Western]] government, as a targeted multi-purpose data collection tool.&amp;lt;ref name=&amp;quot;bbc&amp;quot;&amp;gt;{{cite news|url=https://www.bbc.com/news/technology-30171614|title=BBC News - Regin, new computer spying bug, discovered by Symantec|work=BBC News|date=23 November 2014|access-date=23 November 2014}}&amp;lt;/ref&amp;gt;&amp;lt;ref name=&amp;quot;whitepapers&amp;quot;&amp;gt;{{cite web|url=http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/regin-analysis.pdf|title=Regin White Paper|publisher=Symantec|access-date=23 November 2014|archive-date=7 September 2019|archive-url=https://web.archive.org/web/20190907005119/https://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/regin-analysis.pdf|url-status=dead}}&amp;lt;/ref&amp;gt;&amp;lt;ref name=&amp;quot;whitepaperk&amp;quot;&amp;gt;{{cite web|url=https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/08070305/Kaspersky_Lab_whitepaper_Regin_platform_eng.pdf|title=Regin White Paper|publisher=Kaspersky Lab|access-date=24 November 2014}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to &amp;#039;&amp;#039;[[Die Welt]]&amp;#039;&amp;#039;, security experts at [[Microsoft]] gave it the name &amp;quot;Regin&amp;quot; in 2011, after the cunning Norse dwarf [[Regin]].&amp;lt;ref&amp;gt;{{cite news|author1=Benedikt Fuest|title=Ein Computervirus, so mächtig wie keines zuvor|url=https://www.welt.de/wirtschaft/webwelt/article134685163/Ein-Computervirus-so-maechtig-wie-keines-zuvor.html|newspaper=Die Welt|date=24 November 2014|archive-url=https://web.archive.org/web/20141128080847/http://www.welt.de/wirtschaft/webwelt/article134685163/Ein-Computervirus-so-maechtig-wie-keines-zuvor.html|archive-date=28 November 2014}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Operation==&lt;br /&gt;
Regin uses a modular approach allowing it to load features that exactly fit the target, enabling customized spying. The design makes it highly suited for persistent, long-term mass surveillance operations against targets.&amp;lt;ref&amp;gt;{{cite web|url=http://hackingpost.com/regin-malware-state-sponsored-spying-tool-targeted-govts/|title=Regin Malware - &amp;#039;State-Sponsored&amp;#039; Spying Tool Targeted Govts|work=The Hacking Post - Latest hacking News &amp;amp; Security Updates|access-date=2014-11-24|archive-date=2017-02-18|archive-url=https://web.archive.org/web/20170218064037/http://hackingpost.com/regin-malware-state-sponsored-spying-tool-targeted-govts/|url-status=dead}}&amp;lt;/ref&amp;gt;&amp;lt;ref name=&amp;quot;scmagazine&amp;quot;&amp;gt;{{cite web|url=http://www.scmagazineuk.com/nsa-gchq-or-both-behind-stuxnet-like-regin-malware/article/384888/|title=NSA, GCHQ or both behind Stuxnet-like Regin malware?|publisher=scmagazineuk.com|access-date=25 November 2014|date=24 November 2014}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Regin is stealthy and does not store multiple files on the infected system; instead it uses its own encrypted [[virtual file system]] (EVFS) entirely contained within what looks like a single file with an innocuous name to the host, within which files are identified only by a numeric code, not a name. The EVFS employs a variant encryption of the rarely used [[RC5 cipher]].&amp;lt;ref name=&amp;quot;scmagazine&amp;quot; /&amp;gt; Regin communicates over the Internet using [[Internet Control Message Protocol|ICMP]]/[[Ping (networking utility)|ping]], commands embedded in [[HTTP cookies]] and custom [[Transmission Control Protocol|TCP]] and [[User Datagram Protocol|UDP]] protocols with a [[command and control server]] which can control operations, upload additional [[Payload (computing)|payloads]], etc.&amp;lt;ref name=&amp;quot;symantecblog&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;whitepapers&amp;quot;/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Identification and naming===&lt;br /&gt;
Symantec says that both it and Kaspersky identified the malware as &amp;#039;&amp;#039;Backdoor.Regin&amp;#039;&amp;#039;.&amp;lt;ref name=&amp;quot;symantecblog&amp;quot; /&amp;gt; Most antivirus programs, including Kaspersky, (as of October 2015) do NOT identify the sample of Regin released by The Intercept as malware.&amp;lt;ref&amp;gt;[https://www.virustotal.com/en/file/4139149552b0322f2c5c993abccc0f0d1b38db4476189a9f9901ac0d57a656be/analysis/ Virustotal: Detection ratio: 21 / 56 ]&amp;lt;/ref&amp;gt;  On 9 March 2011 Microsoft added related entries to its Malware Encyclopedia;&amp;lt;ref&amp;gt;[http://www.microsoft.com/security/portal/mmpc/default.aspx Microsoft Malware Protection Center, click button &amp;quot;Malware Encyclopedia]&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;[http://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?name=Trojan%3AWinNT%2FRegin.A#tab=1 Microsoft Protection Center: Trojan:WinNT/Regin.A]&amp;lt;/ref&amp;gt; later two more variants, &amp;#039;&amp;#039;Regin.B&amp;#039;&amp;#039; and &amp;#039;&amp;#039;Regin.C&amp;#039;&amp;#039; were added. Microsoft appears to call the 64-bit variants of Regin &amp;#039;&amp;#039;Prax.A&amp;#039;&amp;#039; and &amp;#039;&amp;#039;Prax.B&amp;#039;&amp;#039;. The Microsoft entries do not have any technical information.&amp;lt;ref name=intercept20041124/&amp;gt; Both Kaspersky and Symantec have published [[white paper]]s with information they learned about the malware.&amp;lt;ref name=&amp;quot;whitepapers&amp;quot;/&amp;gt;&amp;lt;ref name=&amp;quot;whitepaperk&amp;quot;/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Known attacks and originator of malware==&lt;br /&gt;
German news magazine &amp;#039;&amp;#039;[[Der Spiegel]]&amp;#039;&amp;#039; reported in June 2013 that the US [[intelligence]] [[National Security Agency]] (NSA) had conducted online surveillance on both [[European Union]] (EU) citizens and EU institutions. The information derives from [[Global surveillance disclosures (2013–present)|secret documents obtained]] by former NSA worker [[Edward Snowden]]. Both &amp;#039;&amp;#039;Der Spiegel&amp;#039;&amp;#039; and &amp;#039;&amp;#039;[[The Intercept]]&amp;#039;&amp;#039; quote a secret 2010 NSA document stating that it made [[Cyber-attack|cyberattacks]] that year, without specifying the malware used, against the EU diplomatic representations in [[Washington, D.C.]] and its representations to the [[United Nations]].&amp;lt;ref name=&amp;quot;intercept20041124&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;spiegel&amp;quot;&amp;gt;{{cite web|url=http://www.spiegel.de/international/europe/nsa-spied-on-european-union-offices-a-908590.html|title=Attacks from America: NSA Spied on European Union Offices|first1=Laura|last1=Poitras|first2=Marcel|last2=Rosenbach|first3=Fidelius |last3=Schmid|first4=Holger|last4=Stark|publisher=Der Spiegel|date=29 June 2013}}&amp;lt;/ref&amp;gt; Signs identifying the software used as Regin were found by investigators on infected machines.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;The Intercept&amp;#039;&amp;#039; reported that, in 2013, the UK&amp;#039;s [[GCHQ]] attacked [[Belgacom]], Belgium&amp;#039;s largest telecommunications company.&amp;lt;ref name=intercept20041124&amp;gt;{{cite web|url=https://firstlook.org/theintercept/2014/11/24/secret-regin-malware-belgacom-nsa-gchq/|first1=Morgan|last1=Marquis-Boire|first2=Claudio|last2=Guarnieri|first3=Ryan|last3=Gallagher|title=Secret Malware in European Union Attack Linked to U.S. and British Intelligence|publisher=The Intercept|date=24 November 2014}}&amp;lt;/ref&amp;gt; These attacks may have led to Regin coming to the attention of security companies. Based on analysis done by IT security firm Fox IT, &amp;#039;&amp;#039;Der Spiegel&amp;#039;&amp;#039; reported in November 2014, that Regin is a tool of the UK and USA intelligence agencies. Fox IT found Regin on the computers of one of its customers, and according to their analysis parts of Regin are mentioned in the [[NSA ANT catalog]] under the names &amp;quot;Straitbizarre&amp;quot; and &amp;quot;Unitedrake&amp;quot;. Fox IT did not name the customer, but &amp;#039;&amp;#039;Der Spiegel&amp;#039;&amp;#039; mentioned that among the customers of Fox IT is Belgacom and cited the head of Fox IT, Ronald Prins, who stated that they are not allowed to speak about what they found in the Belgacom network.&amp;lt;ref name=nsa-und-gchq&amp;gt;[http://www.spiegel.de/netzwelt/netzpolitik/trojaner-regin-ist-ein-werkzeug-von-nsa-und-gchq-a-1004950.html Christian Stöcker, Marcel Rosenbach &amp;quot; Spionage-Software: Super-Trojaner Regin ist eine NSA-Geheimwaffe&amp;quot; Der Spiegel, November 25, 2014]&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In December 2014, German newspaper &amp;#039;&amp;#039;[[Bild]]&amp;#039;&amp;#039; reported that Regin was found on a [[USB flash drive]] used by a staff member of Chancellor [[Angela Merkel]]. Checks of all high-security laptops in the [[German Chancellery]] revealed no additional infections.&amp;lt;ref&amp;gt;{{cite news |url=http://www.dw.de/german-government-denies-falling-victim-to-cyber-attack/a-18158951 |title=German government denies falling victim to cyber attack |newspaper=Deutsche Welle |date=29 December 2014 }}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Regin was used in October and November 2018 to hack the research and development unit of [[Yandex]].&amp;lt;ref name=&amp;quot;MoscowTimes&amp;quot;&amp;gt;{{cite news |url=https://www.themoscowtimes.com/2019/06/27/western-intelligence-hacked-russias-google-yandex-to-spy-on-accounts-a66194 |title=Western Intelligence Hacked &amp;#039;Russia&amp;#039;s Google&amp;#039; Yandex to Spy on Accounts |agency=Reuters |date=June 27, 2019 |archive-url=https://web.archive.org/web/20190629085027/https://www.themoscowtimes.com/2019/06/27/western-intelligence-hacked-russias-google-yandex-to-spy-on-accounts-a66194 |archive-date=June 29, 2019}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==See also==&lt;br /&gt;
* [[Advanced persistent threat]]&lt;br /&gt;
* [[Cyberwarfare in the United States]]&lt;br /&gt;
* [[NSA ANT catalog]]&lt;br /&gt;
* [[Stuxnet]]&lt;br /&gt;
* [[WARRIOR PRIDE]]&lt;br /&gt;
&lt;br /&gt;
==References==&lt;br /&gt;
{{reflist|30em|}}&lt;br /&gt;
[[Category:Rootkits]]&lt;br /&gt;
[[Category:Computer access control]]&lt;br /&gt;
[[Category:Privilege escalation exploits]]&lt;br /&gt;
[[Category:Cryptographic attacks]]&lt;br /&gt;
[[Category:Exploit-based worms]]&lt;br /&gt;
[[Category:2014 in computing]]&lt;br /&gt;
[[Category:Hacking in the 2010s]]&lt;br /&gt;
[[Category:Spyware used by governments]]&lt;br /&gt;
[[Category:Cybercrime in India]]&lt;/div&gt;</summary>
		<author><name>Ajay Kumar</name></author>
	</entry>
</feed>