Ramblings of an old Doc

 

“An advanced spying tool, Regin displays a degree of technical competence rarely seen and has been used in spying operations against governments, infrastructure operators, businesses, researchers, and private individuals.”- Symantec

The newest piece of super sophisticated spyware, rivaling Stuxnet has been discovered lurking on computers in many sectors (Symantec’s pic 1) and in many places (Symantec pic 2).

 

This happened between 2008-2011 and the vector (how the computers became infected) is unclear. Telcoms were targeted so telephone conversations were probably intercepted.

There are apparently dozens of Regin payloads, as well, with highly specialized targets for information collection. It, like Stuxnet uses modules.

“The threat’s standard capabilities include several Remote Access Trojan (RAT) features, such as capturing screenshots, taking control of the mouse’s point-and-click functions, stealing passwords, monitoring network traffic, and recovering deleted files.

More specific and advanced payload modules were also discovered, such as a Microsoft IIS web server traffic monitor and a traffic sniffer of the administration of mobile telephone base station controllers.” – ibid

How it’s structured:

It also maintained a very low profile…to stay around and suck up goodies for years.

So, There’s no tool yet to see if you’re compromised or not, and Symantec believes that there remain many undiscovered components…so this thing is just getting started.

More power to Norton for finding this.

Source:

http://www.symantec.com/connect/blogs/regin-top-tier-espionage-tool-enables-stealthy-surveillance


Comments
on Nov 23, 2014

NSA at it again? 

on Nov 23, 2014

This would require very sophisticated skills. We're probably talking nation-state level...although which is open to guess at this point.

More than likely, as time goes on, more will get discovered and leaked. 

on Nov 23, 2014

NSA china, CIA, India, FBI, Builderburg group, ...  So many choices, so little time.

on Nov 24, 2014

http://www.bbc.com/news/technology-30171614 mentions russia, saudi arabia and ireland were targets. Which seems like an odd combination. 

on Nov 24, 2014

Well, Heavenfall...no one said they were targeted with the same modules for the same reasons...nor by the same people.

on Dec 06, 2014

Heavenfall

NSA at it again? 

NSA can use built-in backdoors in Windows and SSL, TLS and so on.