Red October (malware): Difference between revisions

Created by Ajay Kumar
Last edited March 16, 2026
Created a new article
 
Ankushraj (talk | contribs)
small fix
 
Line 1: Line 1:
{{short description|Cyberespionage malware}}
{{short description|Cyberespionage malware}}
'''Operation Red October''' or '''Red October''' was a [[cyberespionage]] [[malware]] [[Computer program|program]] discovered in October 2012 and uncovered in January 2013 by Russian firm [[Kaspersky Lab]]. The malware was reportedly operating worldwide for up to five years prior to discovery, transmitting information ranging from diplomatic secrets to personal information, including from mobile devices.  
'''Operation Red October''' or '''Red October''' was a [[cyberespionage]] [[malware]] [[Computer program|program]] discovered in October 2012 and uncovered in January 2013 by Russian firm [[Kaspersky Lab]]. The malware was reportedly operating worldwide for up to five years prior to discovery, transmitting information ranging from diplomatic secrets to personal information, including from mobile devices.  
The primary vectors used to install the malware were emails containing attached documents that exploited vulnerabilities in [[Microsoft Word]] and [[Microsoft Excel|Excel]].<ref name=McAllister>{{cite news | first = Neil | last = McAllister | publisher = [[The Register]] | title = Surprised? Old Java exploit helped spread Red October spyware | url = https://www.theregister.co.uk/2013/01/16/red_october_java_connection | date = 16 Jan 2013}}</ref><ref>{{cite news | publisher = [[Kaspersky Lab]] | title = The "Red October" Campaign – An Advanced Cyber Espionage Network Targeting Diplomatic and Government Agencies | url = https://www.securelist.com/en/blog/785/The_Red_October_Campaign_An_Advanced_Cyber_Espionage_Network_Targeting_Diplomatic_and_Government_Agencies | date = 3 Mar 2014}}</ref>
The primary vectors used to install the malware were emails containing attached documents that exploited vulnerabilities in [[Microsoft Word]] and [[Microsoft Excel|Excel]].<ref name=McAllister>{{cite news | first = Neil | last = McAllister | publisher = [[The Register]] | title = Surprised? Old Java exploit helped spread Red October spyware | url = https://www.theregister.co.uk/2013/01/16/red_october_java_connection | date = 16 Jan 2013}}</ref><ref>{{cite news | publisher = [[Kaspersky Lab]] | title = The "Red October" Campaign – An Advanced Cyber Espionage Network Targeting Diplomatic and Government Agencies | url = https://www.securelist.com/en/blog/785/The_Red_October_Campaign_An_Advanced_Cyber_Espionage_Network_Targeting_Diplomatic_and_Government_Agencies | date = 3 Mar 2014|archive-url=https://web.archive.org/web/20130115005904/https://www.securelist.com/en/blog/785/The_Red_October_Campaign_An_Advanced_Cyber_Espionage_Network_Targeting_Diplomatic_and_Government_Agencies|archive-date=2013-01-15|url-status=dead}}</ref>
Later, a webpage was found that exploited a known vulnerability in the Java browser plugin.<ref name=McAllister /><ref>{{cite news | first = Dan | last = Goodin | publisher = [[Ars Technica]] | title = Red October relied on Java exploit to infect PCs | url = https://arstechnica.com/security/2013/01/massive-espionage-malware-relied-on-java-exploit-to-infect-pcs | date = 15 Jan 2013}}</ref>
Later, a webpage was found that exploited a known vulnerability in the Java browser plugin.<ref name=McAllister /><ref>{{cite news | first = Dan | last = Goodin | publisher = [[Ars Technica]] | title = Red October relied on Java exploit to infect PCs | url = https://arstechnica.com/security/2013/01/massive-espionage-malware-relied-on-java-exploit-to-infect-pcs | date = 15 Jan 2013}}</ref>
Red October was termed an advanced cyberespionage campaign intended to target diplomatic, governmental and scientific research organizations worldwide.
Red October was termed an advanced cyberespionage campaign intended to target diplomatic, governmental and scientific research organizations worldwide.
Line 7: Line 7:
A [https://s3.eu-central-1.amazonaws.com/euobs-media/97b802870897fd63703ecd3497e43286.png map] of the extent of the operation was released by the [[Kaspersky Lab]] – the "Moscow-based antivirus firm that uncovered the campaign."<ref name="wired"/>
A [https://s3.eu-central-1.amazonaws.com/euobs-media/97b802870897fd63703ecd3497e43286.png map] of the extent of the operation was released by the [[Kaspersky Lab]] – the "Moscow-based antivirus firm that uncovered the campaign."<ref name="wired"/>


After being revealed, domain registrars and hosting companies shut down as many as 60 domains, used by the virus creators to receive information. The attackers, themselves, shut down their end of the operation, as well. {{Citation needed|date=August 2016}}
After being revealed, domain registrars and hosting companies shut down as many as 60 domains, used by the virus creators to receive information. The attackers, themselves, shut down their end of the operation, as well.{{Citation needed|date=August 2016}}


The perpetrator of the operation has not been conclusively determined but it appeared to have been in operation on some level since May 2007 at the latest. According to Kaspersky Lab, Russian slang words were found in the code which would be "generally unknown to non-native Russian speakers." However, the program also appeared to be built on existing exploits developed by Chinese [[hackers]] and previously used against [[Tibetan independence movement|Tibetan activists]].<ref name="wired">{{cite news |last1=Zetter |first1=Kim |title=Cybersleuths Uncover 5-Year Spy Operation Targeting Governments, Others |url=https://www.wired.com/2013/01/red-october-spy-campaign/ |access-date=25 January 2023 |work=[[Wired (magazine)|Wired]] |date=January 14, 2013}}</ref>
The perpetrator of the operation has not been conclusively determined but it appeared to have been in operation on some level since May 2007 at the latest. According to Kaspersky Lab, Russian slang words were found in the code which would be "generally unknown to non-native Russian speakers." However, the program also appeared to be built on existing exploits developed by Chinese [[hackers]] and previously used against [[Tibetan independence movement|Tibetan activists]].<ref name="wired">{{cite magazine |last1=Zetter |first1=Kim |title=Cybersleuths Uncover 5-Year Spy Operation Targeting Governments, Others |url=https://www.wired.com/2013/01/red-october-spy-campaign/ |access-date=25 January 2023 |magazine=[[Wired (magazine)|Wired]] |date=January 14, 2013}}</ref>


{| class="wikitable sortable"
{| class="wikitable sortable"
Line 155: Line 155:
[[Category:Espionage in Russia]]
[[Category:Espionage in Russia]]
[[Category:Cybercrime in India]]
[[Category:Cybercrime in India]]
[[Category:2012 in computing]]

Latest revision as of 05:02, 16 March 2026


Operation Red October or Red October was a cyberespionage malware program discovered in October 2012 and uncovered in January 2013 by Russian firm Kaspersky Lab. The malware was reportedly operating worldwide for up to five years prior to discovery, transmitting information ranging from diplomatic secrets to personal information, including from mobile devices. The primary vectors used to install the malware were emails containing attached documents that exploited vulnerabilities in Microsoft Word and Excel.[1][2] Later, a webpage was found that exploited a known vulnerability in the Java browser plugin.[1][3] Red October was termed an advanced cyberespionage campaign intended to target diplomatic, governmental and scientific research organizations worldwide.

A map of the extent of the operation was released by the Kaspersky Lab – the "Moscow-based antivirus firm that uncovered the campaign."[4]

After being revealed, domain registrars and hosting companies shut down as many as 60 domains, used by the virus creators to receive information. The attackers, themselves, shut down their end of the operation, as well.[citation needed]

The perpetrator of the operation has not been conclusively determined but it appeared to have been in operation on some level since May 2007 at the latest. According to Kaspersky Lab, Russian slang words were found in the code which would be "generally unknown to non-native Russian speakers." However, the program also appeared to be built on existing exploits developed by Chinese hackers and previously used against Tibetan activists.[4]

Operation Red October Cyber Breaches[4]
Country Government Embassy (Diplomatic) Military Nuclear / Energy Research Aerospace Oil & Gas Industry Trade and Commerce Research Institutions Unknown Victims
 United States No Yes No No No No No No No
 Russia No Yes Yes Yes No No No Yes No
 Belarus Yes Yes Yes Yes No Yes No Yes No
 Kazakhstan Yes Yes Yes Yes Yes No No No No
 United Arab Emirates Yes Yes No Yes No Yes No No No
 Azerbaijan No Yes No Yes No Yes No Yes No
 Turkmenistan Yes No No Yes No Yes No No No
File:Flag of Afghanistan.svg Afghanistan Yes Yes Yes No No No No No No
 Moldova Yes Yes Yes No No No No No No
 France No Yes Yes No No No No No No
 Spain Yes Yes No No No No No No No
 Armenia Yes Yes No No No No No No No
 Cyprus Yes Yes No No No No No No No
 Iraq Yes No No No No No No No No
 Brunei Yes No No No No No No No No
 Luxembourg Yes No No No No No No No No
 India No Yes No No No No No No No
 Uganda No Yes No No No No No No No
 Pakistan No Yes No No No No No No No
 Oman No Yes No No No No No No No
 Saudi Arabia No Yes No No No No No No No
 Italy No Yes No No No No No No No
 Portugal No Yes No No No No No No No
 Morocco No Yes No No No No No No No
 Israel No Yes No No No No No No No
 Jordan No Yes No No No No No No No
 Greece No Yes No No No No No No No
 Ireland No Yes No No No No No No No
 Belgium No Yes No No No No No No No
 Germany No Yes No No No No No No No
 Hungary No Yes No No No No No No No
 Mauritania No Yes No No No No No No No
 Congo No Yes No No No No No No No
 South Africa No Yes No No No No No No No
 Botswana No Yes No No No No No No No
 Mozambique No Yes No No No No No No No
 Tanzania No Yes No No No No No No No
 Kenya No Yes No No No No No No No
 Lithuania No Yes No No No No No No No
 Latvia No Yes No No No No No No No
 Turkey No Yes No No No No No No No
 Iran No Yes No No No No No No No
 Uzbekistan No Yes No No No No No No No
 Kuwait No Yes No No No No No No No
  Switzerland No Yes No No No No No No No
 Lebanon No Yes No No No No No No No
 Austria No Yes No No No No No No No
 Georgia No Yes No No No No No No No
Template:Country data Bosnia & Herzegovina No Yes No No No No No No No
 Serbia No No No No No No No No Yes
 Finland No No No No No No No No Yes
 Czech Republic No No No No No No No No Yes
 Slovakia No No No No No No No No Yes
 Macedonia No No No No No No No No Yes
 Albania No No No No No No No No Yes
 Mali No No No No No No No No Yes
 Australia No No No No No No No No Yes
 Chile No No No No No No No No Yes
 Brazil No No No No No No No No Yes
 Ethiopia No No No No No No No No Yes
 Bulgaria No No No No No No No No Yes
 Bahrain No No No No No No No No Yes
 Slovakia No No No No No No No No Yes

References[edit | edit source]

  1. 1.0 1.1 McAllister, Neil (16 Jan 2013). "Surprised? Old Java exploit helped spread Red October spyware". The Register.
  2. "The "Red October" Campaign – An Advanced Cyber Espionage Network Targeting Diplomatic and Government Agencies". Kaspersky Lab. 3 Mar 2014. Archived from the original on 2013-01-15.
  3. Goodin, Dan (15 Jan 2013). "Red October relied on Java exploit to infect PCs". Ars Technica.
  4. 4.0 4.1 4.2 Zetter, Kim (January 14, 2013). "Cybersleuths Uncover 5-Year Spy Operation Targeting Governments, Others". Wired. Retrieved 25 January 2023.

External links[edit | edit source]

Template:Hacking in the 2010s