Spy Agencies Hit in Cyber-Espionage Campaign: Kaspersky Lab

Advertisement
By Reuters | Updated: 7 August 2014 20:27 IST

Security researchers at Kaspersky Lab said they have uncovered a cyber-espionage operation that successfully penetrated two spy agencies and hundreds of government and military targets in Europe and the Middle East since the beginning of this year.

The hackers, according to Kaspersky, were likely backed by a nation state and used techniques and tools similar to ones employed in two other high-profile cyber-espionage operations that Western intelligence sources have linked to the Russian government.

Kaspersky, a Moscow-based security software maker that also sells cyber-intelligence reports, declined to say if it believed Russia was behind the espionage campaign.

Advertisement

Dubbed "Epic Turla," the operation stole vast quantities of data, including word processing documents, spreadsheets and emails, Kaspersky said, adding that the malware searched for documents with terms such as "NATO," "EU energy dialogue" and "Budapest."

Advertisement

(Also See: Symantec, Kaspersky Downplay Beijing Move to Exclude Their Products)

"We saw them stealing pretty much every document they could get their hands," Costin Raiu, head of Kaspersky Lab's threat research team, told Reuters ahead of the release of a report on "Epic Turla" on Thursday during the Black Hat hacking conference in Las Vegas.

Advertisement

Kaspersky said the ongoing operation is the first cyber-espionage campaign uncovered to date that managed to penetrate intelligence agencies. It declined to name those agencies, but said one was located in the Middle East and the other in the European Union.

Other victims include foreign affairs ministries and embassies, interior ministries, trade offices, military contractors and pharmaceutical companies, according to Kaspersky. It said the largest number of victims were located in France, the United States, Russia, Belarus, Germany, Romania and Poland.

Advertisement

Kaspersky said the hackers used a set of software tools known as "Carbon" or "Cobra," which have been deployed in at least two high-profile attacks. The first was an attack against the U.S. military's Central Command that was discovered in 2008. The second attack was against Ukraine and other nations, uncovered earlier this year, using malicious software dubbed "Snake" or "Uroburos."

Western intelligence sources told Reuters in March that they believed the Russian government was behind those two attacks. Russia's Federal Security Bureau had declined to comment at the time.

(Also See: Beijing to Bar Symantec, Kaspersky Anti-Virus in Procurement: Report)

Symantec Corp, the biggest U.S. security software maker, said it also planned to release a report on "Epic Turla" and related campaigns on Thursday, following months of research. Symantec declined to say if the hackers were linked to Russia and would not name specific victims.

Many cybersecurity researchers refrain from commenting on who they believe are behind cyber-attacks, saying they lack the intelligence needed to draw such conclusions.

The Kaspersky report suggests the hackers spoke Russian, though that could mean people from a number of countries. It said the control panels in software for running the "Epic Turla" campaign were set to use Russian Cyrillic characters and its code include the Russian word "Zagruzchick," which means "boot loader."

Symantec researcher Vikram Thakur said the hackers infected machines by first compromising websites that victims would likely visit, including sites of some government agencies. The software was designed to scan a computer to determine if it belonged to somebody who was of interest, such as a government employee, Thakur said.

Once a PC is compromised, "Epic Turla" analyzed the machine to see if it has data of interest to the hackers, distributing more Carbon components to further study the machine if it had such information, according to Kaspersky.

© Thomson Reuters 2014

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo Find X9 Series Price in India Leaked Again Ahead of Debut
  2. OnePlus Ace 6T Launch Timeline Revealed; Will Sport This Snapdragon Chip
  3. Oppo Reno 15 Series Launched With Up To 6,500mAh Battery: See Price, Features
  4. Astronomers Capture First-Ever Early Snapshot of Supernova Shock Wave Using ESO's VLT
  5. A Very Jonas Christmas Movie Streaming Now on JioHotstar: Everything You Need to Know
  1. Astronomers Uncover the Vast Greater Pleiades Complex with 3,000 Hidden Stars
  2. Astronomers Capture First-Ever Early Snapshot of Supernova Shock Wave Using ESO’s VLT
  3. Artemis Era Raises Safety Concerns as Lunar Orbit Nears Capacity, New Study Finds
  4. SpaceX Sends Sentinel-6B to Orbit for Precision Sea-Level Tracking
  5. India Approves Chandrayaan-4 Moon Sample Mission and National Space Station
  6. Landman Season 2 Now Streaming on JioHotstar: Everything You Need to Know About This American Political Drama Series
  7. Nadu Center OTT Release Date: Know When to Watch This JioHotstar Specials Tamil Series Online
  8. Usiru OTT Release Date Revealed: Know Where to Watch This Kannada Thriller Online
  9. Boron Arsenide Surpasses Diamond in Heat Conductivity, Paving Way for Advanced Electronics
  10. Astronomers Spot First Coronal Mass Ejection from a Distant Star, Raising Questions About Planetary Habitability
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.