Operation Red October or Red October was a cyberespionage malware program discovered in October 2012 and uncovered in January 2013 by Russian firm Kaspersky Lab. The malware was reportedly operating worldwide for up to five years prior to discovery, transmitting information ranging from diplomatic secrets to personal information, including from mobile devices. The primary vectors used to install the malware were emails containing attached documents that exploited vulnerabilities in Microsoft Word and Excel.[1][2] Later, a webpage was found that exploited a known vulnerability in the Java browser plugin.[1][3] Red October was termed an advanced cyberespionage campaign intended to target diplomatic, governmental and scientific research organizations worldwide.
A map of the extent of the operation was released by the Kaspersky Lab – the "Moscow-based antivirus firm that uncovered the campaign."[4]
After being revealed, domain registrars and hosting companies shut down as many as 60 domains, used by the virus creators to receive information. The attackers, themselves, shut down their end of the operation, as well.[citation needed]
The perpetrator of the operation has not been conclusively determined but it appeared to have been in operation on some level since May 2007 at the latest. According to Kaspersky Lab, Russian slang words were found in the code which would be "generally unknown to non-native Russian speakers." However, the program also appeared to be built on existing exploits developed by Chinese hackers and previously used against Tibetan activists.[4]
| Country | Government | Embassy (Diplomatic) | Military | Nuclear / Energy Research | Aerospace | Oil & Gas Industry | Trade and Commerce | Research Institutions | Unknown Victims |
|---|---|---|---|---|---|---|---|---|---|
| 👁 Image United States |
No | Yes | No | No | No | No | No | No | No |
| 👁 Image Russia |
No | Yes | Yes | Yes | No | No | No | Yes | No |
| 👁 Image Belarus |
Yes | Yes | Yes | Yes | No | Yes | No | Yes | No |
| 👁 Image Kazakhstan |
Yes | Yes | Yes | Yes | Yes | No | No | No | No |
| 👁 Image United Arab Emirates |
Yes | Yes | No | Yes | No | Yes | No | No | No |
| 👁 Image Azerbaijan |
No | Yes | No | Yes | No | Yes | No | Yes | No |
| 👁 Image Turkmenistan |
Yes | No | No | Yes | No | Yes | No | No | No |
| 👁 Image Afghanistan |
Yes | Yes | Yes | No | No | No | No | No | No |
| 👁 Image Moldova |
Yes | Yes | Yes | No | No | No | No | No | No |
| 👁 Image France |
No | Yes | Yes | No | No | No | No | No | No |
| 👁 Image Spain |
Yes | Yes | No | No | No | No | No | No | No |
| 👁 Image Armenia |
Yes | Yes | No | No | No | No | No | No | No |
| 👁 Image Cyprus |
Yes | Yes | No | No | No | No | No | No | No |
| 👁 Image Iraq |
Yes | No | No | No | No | No | No | No | No |
| 👁 Image Brunei |
Yes | No | No | No | No | No | No | No | No |
| 👁 Image Luxembourg |
Yes | No | No | No | No | No | No | No | No |
| 👁 Image India |
No | Yes | No | No | No | No | No | No | No |
| 👁 Image Uganda |
No | Yes | No | No | No | No | No | No | No |
| 👁 Image Pakistan |
No | Yes | No | No | No | No | No | No | No |
| 👁 Image Oman |
No | Yes | No | No | No | No | No | No | No |
| 👁 Image Saudi Arabia |
No | Yes | No | No | No | No | No | No | No |
| 👁 Image Italy |
No | Yes | No | No | No | No | No | No | No |
| 👁 Image Portugal |
No | Yes | No | No | No | No | No | No | No |
| 👁 Image Morocco |
No | Yes | No | No | No | No | No | No | No |
| 👁 Image Israel |
No | Yes | No | No | No | No | No | No | No |
| 👁 Image Jordan |
No | Yes | No | No | No | No | No | No | No |
| 👁 Image Greece |
No | Yes | No | No | No | No | No | No | No |
| 👁 Image Ireland |
No | Yes | No | No | No | No | No | No | No |
| 👁 Image Belgium |
No | Yes | No | No | No | No | No | No | No |
| 👁 Image Germany |
No | Yes | No | No | No | No | No | No | No |
| 👁 Image Hungary |
No | Yes | No | No | No | No | No | No | No |
| 👁 Image Mauritania |
No | Yes | No | No | No | No | No | No | No |
| 👁 Image Congo |
No | Yes | No | No | No | No | No | No | No |
| 👁 Image South Africa |
No | Yes | No | No | No | No | No | No | No |
| 👁 Image Botswana |
No | Yes | No | No | No | No | No | No | No |
| 👁 Image Mozambique |
No | Yes | No | No | No | No | No | No | No |
| 👁 Image Tanzania |
No | Yes | No | No | No | No | No | No | No |
| 👁 Image Kenya |
No | Yes | No | No | No | No | No | No | No |
| 👁 Image Lithuania |
No | Yes | No | No | No | No | No | No | No |
| 👁 Image Latvia |
No | Yes | No | No | No | No | No | No | No |
| 👁 Image Turkey |
No | Yes | No | No | No | No | No | No | No |
| 👁 Image Iran |
No | Yes | No | No | No | No | No | No | No |
| 👁 Image Uzbekistan |
No | Yes | No | No | No | No | No | No | No |
| 👁 Image Kuwait |
No | Yes | No | No | No | No | No | No | No |
| 👁 Image Switzerland |
No | Yes | No | No | No | No | No | No | No |
| 👁 Image Lebanon |
No | Yes | No | No | No | No | No | No | No |
| 👁 Image Austria |
No | Yes | No | No | No | No | No | No | No |
| 👁 Image Georgia |
No | Yes | No | No | No | No | No | No | No |
| 👁 Image Bosnia & Herzegovina |
No | Yes | No | No | No | No | No | No | No |
| 👁 Image Serbia |
No | No | No | No | No | No | No | No | Yes |
| 👁 Image Finland |
No | No | No | No | No | No | No | No | Yes |
| 👁 Image Czech Republic |
No | No | No | No | No | No | No | No | Yes |
| 👁 Image Slovakia |
No | No | No | No | No | No | No | No | Yes |
| 👁 Image Macedonia |
No | No | No | No | No | No | No | No | Yes |
| 👁 Image Albania |
No | No | No | No | No | No | No | No | Yes |
| 👁 Image Mali |
No | No | No | No | No | No | No | No | Yes |
| 👁 Image Australia |
No | No | No | No | No | No | No | No | Yes |
| 👁 Image Chile |
No | No | No | No | No | No | No | No | Yes |
| 👁 Image Brazil |
No | No | No | No | No | No | No | No | Yes |
| 👁 Image Ethiopia |
No | No | No | No | No | No | No | No | Yes |
| 👁 Image Bulgaria |
No | No | No | No | No | No | No | No | Yes |
| 👁 Image Bahrain |
No | No | No | No | No | No | No | No | Yes |
| 👁 Image Slovakia |
No | No | No | No | No | No | No | No | Yes |
References
[edit]- ^ a b McAllister, Neil (16 Jan 2013). "Surprised? Old Java exploit helped spread Red October spyware". The Register.
- ^ "The "Red October" Campaign – An Advanced Cyber Espionage Network Targeting Diplomatic and Government Agencies". Kaspersky Lab. 3 Mar 2014. Archived from the original on 2013-01-15.
- ^ Goodin, Dan (15 Jan 2013). "Red October relied on Java exploit to infect PCs". Ars Technica.
- ^ a b c Zetter, Kim (January 14, 2013). "Cybersleuths Uncover 5-Year Spy Operation Targeting Governments, Others". Wired. Retrieved 25 January 2023.
