• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

The millennial generation is split in 2: an older crowd with boomer-style comfort, a younger set going 'back to the early 1900s'

2

Trump pulls back after Iran crosses his red line as U.S. military breaks two-week streak of airstrikes amid talks for potential Hormuz deal

3

College-educated women are snapping up the highest-earning men without college degrees, leaving the rest further behind

1

The millennial generation is split in 2: an older crowd with boomer-style comfort, a younger set going 'back to the early 1900s'

2

Trump pulls back after Iran crosses his red line as U.S. military breaks two-week streak of airstrikes amid talks for potential Hormuz deal

3

College-educated women are snapping up the highest-earning men without college degrees, leaving the rest further behind
The Cloud Series

Regin, a new piece of spyware, said to infect telecom, energy, airline industries

By
DJ Summers
DJ Summers
Down Arrow Button Icon
By
DJ Summers
DJ Summers
Down Arrow Button Icon
November 23, 2014, 12:00 PM ET
185288188
PHP CodePhotograph by Scott Cartwright — Getty Images
Add Fortune on Google for similar content.

The cyber security firm Symantec on Sunday revealed that a malicious new piece of software is collecting information on individuals, companies, and government entities without their knowledge.

The malware, called Regin, is considered to be a mass surveillance and data collection tool (sometimes referred to as “spyware”). Its purpose and origin is still unclear, Symantec said, but researchers believe that the program is the work of a nation-state.

“We believe Regin is used primarily for espionage,” said Liam O’Murchu, a security researcher at Symantec. “We see both companies and individuals targeted. The ultimate goal is to listen in on phone calls or something like that. [Regin’s operators] target individuals and spread the attack to find whatever it is they’re looking for. All of these things together make us think that a government wrote it.”

Symantec (SYMC) said Regin (pronounced “re-gen,” as in “regenerate”) monitors its targets with a rarely-seen level of sophistication. Internet service providers and telecommunications companies make up the bulk of the those that are initially infected, researchers said. Regin then targets individuals of interest—in the hospitality, energy, research, and airline industries, among others—that are served by those ISPs. Regin’s operators continue to use infected companies as a springboard to gain access to more individuals. Once they gain access, they can remotely control a person’s keyboard, monitor Internet activity, and recover deleted files.

More than half of observed attacks have targeted Russia and Saudi Arabia, Symantec said. The rest are scattered across Europe, Central America, Africa, and Asia. The initial infection can come from a wide variety of sources, such as copies of popular websites or web browsers and USB drives that have been plugged into contaminated systems.

Regin has five attack stages. It begins with an initial “drop,” also called a Trojan horse (or “backdoor”) breach, that allows it to exploit a security vulnerability while avoiding detection. The first stage deploys what is called a loader, which prepares and executes the next stage; the second stage does the same to complicate detection. The third and fourth stages, called kernels, build a framework for the fifth and final stage, called the payload. That’s when it can wrest control of a computer or leap to a new victim.

Each stage prepares and executes the next, rather than deploy from a common framework. It’s similar in concept to Russian nesting dolls. Regin’s distributed structure makes it difficult for cyber security researchers to identify it without capturing information about all five stages.

The malware is made up of a system of customizable modules so that it may collect the information it needs across a number of different victims. For example, one Regin attack might capture a password from a hotel clerk’s computer while another attack may obtain remote control of another computer’s keyboard for purposes unknown. Each module is customized for one task or system, making detection and prevention of a comprehensive Regin attack difficult.

“One of the problems we have with analyzing is we don’t have all the components,” O’Murchu said. “You only get the modules set on that [particular] victim. But we know there are far more modules than what we have here. We don’t have enough information to understand. On top of that, it’s coded in a very advanced way to leave a small footprint. Anything they leave behind is encrypted. Each part is dependent on having all the parts.”

This kind of operational complexity is typically reserved for a state or a state-sponsored actor, Symantec said. Only a handful of malware programs to date have demonstrated such sophistication. In 2012, the Flamer malware used the same modular system to hit targets in the West Bank of Palestine, Hungary, Iran, and Lebanon, among other countries. Regin’s multi-stage attack pattern operates similarly to the Duqu malware and its descendent Stuxnet, the malware responsible for the disruption of Iranian nuclear facilities in 2010. O’Murchu said Regin is part of a disquieting trend of government-written and government-enacted malware.

“We often say that Stuxnet opened Pandora’s box,” O’Murchu says. “Whether that is because we know what to look for now or because there has been a genuine increase since Stuxnet is up for debate, but what we can say is that yes, we now know about a lot more scary government malware than before. It is far more pervasive, it is embedded in more organizations than we have ever seen, it is more organized than ever, and it is more capable than ever. I would say there has been an explosion in government related malware, and it doesn’t seem to be going away anytime soon.”

What makes Regin different is who it attacks. Instead of going only after high-worth targets, Regin attacks many different targets in an attempt to piece together contextual information. Of the 9% of Regin attacks in the hospitality industry, 4% targeted low-level computers, presumably for this information.

“The average person needs to be aware,” O’Murchu says. “A lot of the infections are not the final target. They are third parties providing some extra information to get to a final target. Lot of people think, ‘I don’t have anything of importance, why would anyone get on my computer?’ Ordinary people who may not think they’re targets in fact are.”

About the Author
By DJ Summers
See full bioRight Arrow Button Icon
Add Fortune on Google for similar content.

Latest in

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • TikTok icon
  • YouTube icon

Latest in

China’s Moonshot, Z.AI, and DeepSeek are challenging U.S. AI labs—and beating them on cost
MagazineChina
China’s Moonshot, Z.AI, and DeepSeek are challenging U.S. AI labs—and beating them on cost
By Nicholas GordonJuly 26, 2026
60 minutes ago
Mideast oil may soon have no way out amid ‘everything everywhere all at once’ wars, but the crisis in refined products is even worse
Middle EastOil
Mideast oil may soon have no way out amid ‘everything everywhere all at once’ wars, but the crisis in refined products is even worse
By Jason MaJuly 26, 2026
1 hour ago
Traders are getting a new tool to wager on the biggest U.S. stocks
Investingstock trading
Traders are getting a new tool to wager on the biggest U.S. stocks
By Bernard Goyder, Katherine Doherty and BloombergJuly 26, 2026
3 hours ago
Big Tech earnings slam into a market in revolt over AI spending
Big Techearnings
Big Tech earnings slam into a market in revolt over AI spending
By Jeran Wittenstein, Ryan Vlastelica and BloombergJuly 26, 2026
3 hours ago
Romania scrambles F-16 jets to shoot down a suspected Russian ‘Shahed type’ drone, marking the fourth recent violation of NATO airspace
PoliticsRussia
Romania scrambles F-16 jets to shoot down a suspected Russian ‘Shahed type’ drone, marking the fourth recent violation of NATO airspace
By Sam McNeil, Vadim Ghirda and The Associated PressJuly 26, 2026
4 hours ago
James Cameron tried to warn us: ‘Skynet Day’ is now shorthand for OpenAI’s agent going rogue and hacking into a startup
AIOpenAI
James Cameron tried to warn us: ‘Skynet Day’ is now shorthand for OpenAI’s agent going rogue and hacking into a startup
By Laurie Kellman, Lindsey Bahr and The Associated PressJuly 26, 2026
4 hours ago

Most Popular

The millennial generation is split in 2: an older crowd with boomer-style comfort, a younger set going 'back to the early 1900s'
Real Estate
The millennial generation is split in 2: an older crowd with boomer-style comfort, a younger set going 'back to the early 1900s'
By Nick LichtenbergJuly 25, 2026
1 day ago
Trump pulls back after Iran crosses his red line as U.S. military breaks two-week streak of airstrikes amid talks for potential Hormuz deal
Middle East
Trump pulls back after Iran crosses his red line as U.S. military breaks two-week streak of airstrikes amid talks for potential Hormuz deal
By Jason MaJuly 25, 2026
1 day ago
College-educated women are snapping up the highest-earning men without college degrees, leaving the rest further behind
Economy
College-educated women are snapping up the highest-earning men without college degrees, leaving the rest further behind
By Mia OsmonbekovJuly 26, 2026
12 hours ago
An 11-year-old is cleaning his neighbors' trash cans for $10 each—he now has 100K followers as teens face the worst summer job market since 1948
Success
An 11-year-old is cleaning his neighbors' trash cans for $10 each—he now has 100K followers as teens face the worst summer job market since 1948
By Orianna Rosa RoyleJuly 25, 2026
2 days ago
'The demographic dividend of the last 40 years is ending': J.P. Morgan says the world is running out of the two things that kept interest rates down
Economy
'The demographic dividend of the last 40 years is ending': J.P. Morgan says the world is running out of the two things that kept interest rates down
By Eleanor PringleJuly 24, 2026
3 days ago
Startups are installing tiny data centers in people’s homes to reduce strain on the beleaguered electrical grid
Environment
Startups are installing tiny data centers in people’s homes to reduce strain on the beleaguered electrical grid
By Sasha RogelbergJuly 25, 2026
1 day ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.