Kaspersky Labs issued a report Monday announcing detection of a high-level cyber-espionage campaign has successfully infiltrated computer networks at diplomatic, governmental and scientific research organizations, gathering data and intelligence from mobile devices, computer systems and network equipment.
The campaign, identified as “Rocra”, short for “Red October”, is currently still active with data being sent to multiple command-and-control servers, through a configuration which rivals in complexity the infrastructure of the Flame malware, the report issued by Kaspersky Labs says.
The campaign targeted specific organizations mostly in Eastern Europe, former USSR members and countries in Central Asia, but also in Western Europe and North America.
Kaspersky Labs issued a list of states affected by the attack. Russia is the country mostly affected by infections (38) and is followed by Kazakhstan and Azerbaijan (15 infections each). Ten infections were revealed in Armenia.
“The information stolen by the attackers is obviously of the highest level and includes geopolitical data which can be used by nation states. Such information could be traded in the underground and sold to the highest bidder, which can be of course, anywhere,” the report reads.

















