The New York Times became a victim of hackers from the PRC. Meanwhile, another “Red October” surfaced in Russia

Office The New York Times in New York
The attack on The New York Times has nothing to do with the desire of some “anonymouses” to interfere with the normal operation of the newspaper, as it occurs periodically in Russia, when long DDOS attacks on editorial networks of large publications or radio stations led to a long downtaim (inaccessibility) of their sites. In the case of The New York Times, we are talking about obtaining an unauthorized access to the local network of the editorial office and computers of the newspaper employees. The New York Times, having discovered the first signs of hacking, hired an authoritative American company Mandiant, specializing in outsourcing IT security. The results of the analysis and gave reporters an occasion for a statement about the "Chinese" traces.
The "chip" issued
It was not difficult to conclude about the reasons for the attack: the first external penetration into the newspaper’s computers, as it was possible to find out, occurred on September 13 - that is, coincided with the period when the newspaper was preparing material about the relatives of the Prime Minister of China Wen Jebao, which, according to sources of the publication, could be about $ 2.7 billion. Another one and a half months, the article was published, and already in the first minutes after its publication in the publication in the publication in the first minutes. The Chinese Internet segment was blocked not only to access to the newspaper website, but also by search queries regarding The New York Times and the Van family.
The statement by The New York Times on the facts of unauthorized access to computers of its employees immediately responded an angry rebuke of the PRC Foreign Ministry - they say, the arguments of the newspaper about China's involvement are “irresponsible”. And the organ of the CPC Central Committee of the Zenmin Zhibao newspaper issued an indignant material in which the United States accused the desire to use the “Chinese threat” as an excuse to build up its Cybervo and the desire to limit the technological development of the PRC, which, they say, the Americans envy. However, the indignation of the Chinese does not look very convincing. Judging by the leagues of access from the hacked devices of the newspaper’s office, tunneling of access to the resources of The New York Times so as to create the appearance of attacks from American universities, which, according to the representative of Mandiant, is a traditional “chip” of Chinese hackers.
Who "leaked"? The New York Times, noticing the attack only after publishing an article about the premiere of China, decided to observe the actions of attackers who gained access to computers 53 newspaper employees, including the computer of David Barboza, the author of the scandalous article. “Sightly professional work,” comments on the actions of Chinese hackers, the technical director of the Creative Telematics & Trade, Mikhail Fedorov. -It is enough to compromise (hack.-The New Times) one or two cars personally, after which, if you work carefully, you can remain unnoticed for a very long time and slowly study everything that is available: the infrastructure of the local network, the location of the main server, the postal server ... Sometimes the presence of an outsider in the system remains inconspicuous for the owner of the computer for years. "
Judging by the history of the “guests” from the Middle Kingdom in the networks of the newspaper, hacking was aimed exclusively at the search for data on journalistic sources, that is, the Chinese were primarily interested in who “merged” information to journalists. As follows from the report of The New York Times, uninvited guests began to work at 8 am Beijing time - a clear hint that the activity was carried out from certain offices or centers with a normalized working day, no matter how funny it sounds. This fact involuntarily recalls the posts of Andrei Blogin’s LJ and blogger - he has repeatedly noted that the domestic “federal” and “our” bots, the purpose of which is to litter the discussion venues on the Internet, at first worked exclusively on weekdays and even with a break for lunch.
New trend
The New York Times is not the first American media that suffered from the actions of Chinese hackers. The Wall Street Journal, after colleagues, also announced the unauthorized monitoring of its computers, pointing out the similar nature of hacking and the hackers tracking “Chinese” materials. Representatives of the Bloomberg news agency made similar statements.
In early February, the Twitter microblog service also announced his attack on his security system: Bob Lord, the company's information security director, said on a corporate blog that attackers could gain access to about a quarter of a million user accounts. This forced Twitter to carry out a mass change of blogger passwords and share your data on attack with US law enforcement agencies.
In fairness, we note: illegal information technologies in the service of the state are not Chinese know-how. Suspicions have not yet been eliminated that the development of the Stuxnet virus, which in the year before last, infected the computers of Iranian nuclear scientists, purposefully sponsored the United States and Israel. And after all, the cyber weapon worked - Iran’s nuclear program lost its fifth part of its nuclear centrifuges, receiving thousands of infected computers in return. It is possible that the successful cyber attack on Iran was so impressed by the imagination of politicians that a new trend arose in the world - an attempt to solve international conflicts using information technology. It is no coincidence that Flame and Gauss were added to Stuxnet last year-the programs-owners operating mainly in the Middle East (there are suspicions that these viruses are widespread by the United States and Israel). A separate question - is it possible to fight them effectively?
*" A new trend arose in the world - an attempt to solve international conflicts using information technology *” Michens - embassies
It is believed that Stuxnet and Flame deciphered the Kaspersky Laboratory, it also issued information about the new computer supervirus called Red October (abbreviated Rocra) in mid -January.
The spy program, as it turned out, has been operating for more than five years. It was possible to find it only in October last year largely thanks to the efforts of an employee of the laboratory of Romanian Kostin Ryu. It was he who was able to experimentally identify the scheme of the virus and its main goals. The virus is mainly aimed at the network of government, military and diplomatic structures, energy companies, including nuclear developments, research institutions, large industrial and trade firms. In addition to geopolitical information, attackers are interested in access to corporate computer networks and individual mobile devices.
Most of all, according to the Kaspersky Laboratory, Russia, the states of the former USSR, Eastern Europe and Central Asia, as well as the United Arab Emirates are affected today. The German “Spiegel” gives an example: tens of thousands of documents from the correspondence of the Russian embassy in the United States, including secret reports of the Ministry of Defense, fell into the hands of cyberspes. The content of these documents can be as explosive as the dispatches of American diplomats laid out on the WikiLeaks Internet site.
However, the embassies are generally one of the main objects of the “Red October” attacks. In this segment, 45 countries are affected.

Virus in the fog
If in Stuxnet many experts recognize the American and Israeli handwriting, then in the encoding of Red October, these or another words of Russian computer slang are visible now and then. For example, Zakladka, which is deciphered as a bug for listening, or Proga is a program. The programming style is far from uniformity - evidence that the authors of the program did not have direct contact with each other. It is assumed that the organizer of the entire action was a certain special service that was able to attract Russian hackers with a high level of computer training, but cannot find themselves in the Russian software services market. The Western sources provide data from the Russian Ministry of Internal Affairs, from which it follows that 30% of the total world cybercrimin have Russian roots. It is also expressed that these are the tricks of all the same Chinese who, using their hackers, methods similar to the “Krasno -Ottabrsky”, penetrated the network of Tibetan activists.
According to Kaspersky experts, Red October software has a specific architecture consisting of hacker modules and extensions that can steal information of a high degree of secrecy.
According to Andreas Marx, managing the AV-Test company in Magdeburg, viruses in the computer network fell using special phishing letters that were sent to specific addressees. The Trojan program was inserted into such a letter, which was prescribed in the system using exploits working on the system “holes” of Microsoft Office. Kaspersky experts found the “victims” and watched infected computers who got in touch with team servers. In particular, he did the same Ryu. For two months - from November 2, 2012 to 01/10/2013 - more than 55 thousand connections with 250 infected computers were recorded. Kostin Riu believes that so far it was possible to penetrate only six out of 60 command vehicles. Once “under the cap”, “Red October” turned into “hibernation” as if. But this is not for long. The multifunctional platform, which was developed by cyberspions, has the ability not only to adapt to the configuration of the system and steal data, but also has a recovery module. It looks like a plugin for Adobe Reader in Microsoft Office. If the main virus is detected and removed from the computer or the entire system is reinstalled, that is, the computer has been “cured”, the indestructible virus-plagin re-provides hackers with access to the system. Hackers have the ability to kidnap even deleted files from USB drives, as well as information about network industrial equipment (switches, routers), not to mention mobile devices, primarily smartphones (Nokia, Windows Phone, iPhone).
It would seem that the picture is clear. But not everything is so simple.
The ghost of self -promotion
“Antivirus programs create only the visibility of security, which is not in reality,” said Fred Cohen, security expert in the editorial council of the “Computer Virology Journal”. “Many users load everything that is possible into their computers, in the hope that it will protect them.” Cohen knows what he was talking about. After all, it was he who 30 years ago, working at the University of Southern California, he introduced the concept of “computer virus”: “There is always a new virus that will outwit it for every protection.” The main, in his opinion, protection is skepticism and caution.
But the observer of the Baltimore CHRISTIAN Science Monitor Fred Wayir seems strange that for the third time, following Stuxnet and Flame, it is the Kaspersky Laboratory (by the way, there are a lot of customers in the Middle East) discovering global kibaghrugerosis: the exposure of Flame, from the American point of view, was "Very untimely." Innecious observers can make this ask the question: should this company consider this company an instrument or even an agent of Russian intelligence?
We should not forget that the “Kaspersky Laboratory” is a joint -stock company, which, like any private business, needs orders and, of course, for advertising. In this regard, Wair also cites the words of Major General KGB Alexei Kondaurov. “It seems strange to me,” says the general, “that such a large -scale operation was exposed by a private company that worked on a private order. Where is FAPSI, CIA and other services that should deal with such threats? Perhaps the Kaspersky Laboratory is simply interested in self -promotion, and therefore so much noise has risen around this. ”