Threat Picture
Latest Cybersecurity News

Costin Raiu: Taking Apart the Malware Used by Spies

A school virus launched his interest in security. At Kaspersky, his team exposed espionage campaigns reaching far beyond one network.
By Charles Joseph · Updated
Share
Share
Copy URL

Costin Raiu spent the better part of a quarter century doing the thing spy agencies like least: taking their malware apart in public.

As the head of Kaspersky's Global Research and Analysis Team, he and his researchers exposed Red October, the Mask, Duqu 2.0 and the Equation Group, the crew whose tools could rewrite the firmware of your hard drive. Each report made headlines around the world.

That kind of work gets you noticed. Strangers paid cash to sit in on his talk, and someone broke into his home and left him a message. Through all of it, the Romanian who started out cleaning a virus off his high school's network kept publishing.

Costin Raiu at a Glance

  • In the early 1990s a virus called BadSectors infected his high school's network, and the teachers asked the student who knew computers to write a cure. He did, and the favor grew into an antivirus product.
  • He joined Kaspersky in 2000 as its chief security expert for Eastern Europe, the Middle East and Africa, and in 2010 took charge of the Global Research and Analysis Team, GReAT.
  • Under his watch Kaspersky exposed Flame (2012), Red October (2013), the Mask (2014) and the Equation Group (2015), some of the most sophisticated spying operations ever made public.
  • In 2015 the team caught Duqu 2.0 inside Kaspersky's own network. The same platform had been used against venues of the Iran nuclear talks.
  • The work drew unwelcome attention: strangers paid cash to attend his 2010 Stuxnet talk, and his home was broken into.
  • Meanwhile Washington turned on his employer, ordering Kaspersky software off federal systems in 2017 and banning its sale in the United States in 2024.
  • After 13 years running GReAT, Raiu stepped down. He now co-hosts the Three Buddy Problem podcast and still turns up in the news whenever state hackers do.
Sponsored

The Life of Costin Raiu

Raiu's Early Years

Raiu got into security, as he puts it, "by accident." In the early 1990s his high school's computer network was hit by a nasty virus called BadSectors.

None of the antivirus programs of the day could clean it, so the teachers turned to the student who knew his way around computers. "That's how I wrote my first antivirus," he said in a 2021 interview, "and from that moment on, more and more people asked if I could write them a custom solution for their problems."

Those requests slowly turned into a real antivirus product, and then into a career.

Joining Kaspersky

In 2000, Raiu joined Kaspersky Lab, the Moscow antivirus company, as chief security expert overseeing research across Eastern Europe, the Middle East and Africa.

In 2010 he became director of the Global Research and Analysis Team, GReAT, the company's unit for hunting the most advanced attackers. His timing was remarkable: that year Stuxnet surfaced, and the age of state-built malware went public.

Raiu led Kaspersky's Stuxnet research and presented it at the Virus Bulletin conference in Vancouver that fall. Three people registered at the last minute, paid several thousand dollars in cash, appeared to come from a Middle Eastern country and sat through only one talk: his.

Sponsored

Flame, Red October and the Mask

In May 2012, while hunting a data-wiping program at the request of the UN's telecom agency, Kaspersky found Flame, a 20-megabyte espionage toolkit that'd been sniffing networks, taking screenshots and recording audio across the Middle East.

In January 2013 GReAT unveiled Red October, a spy network that'd been quietly looting diplomatic and government networks for at least five years, with several hundred confirmed infections across 39 countries.

A year later came the Mask, or Careto, named for a Spanish slang word for "mask" or "ugly face" that its authors left in the code. Kaspersky ranked it above Duqu and called it "one of the most advanced APTs at the current time," with more than 380 victims in 31 countries.

Raiu was often the one explaining the findings on camera and to reporters, from how the code worked to, carefully, who might be behind it. The reports rarely named a government. They laid out the evidence, and readers did the math.

The Equation Group

On February 16, 2015, GReAT published its most explosive report: the Equation Group, which Kaspersky said had been active for almost two decades and had infected thousands, perhaps tens of thousands, of victims since 2001 in fields from government and telecoms to aerospace, energy and nuclear research.

The showstopper was a module that could reprogram the firmware of hard drives from Seagate, Western Digital, Toshiba and others, which Kaspersky called "an astonishing technical accomplishment." PCWorld's headline put it bluntly: "Destroying your hard drive is the only way to stop this super-advanced malware."

The team also showed that two zero-day exploits in an Equation worm called Fanny had been used before they turned up in Stuxnet. Kaspersky called the group "probably one of the most sophisticated cyber attack groups in the world" but didn't say which country ran it.

Duqu 2.0 Comes Home

Two months later the hunters became the hunted. "It was late, maybe eleven o'clock at night, when I got a message," Raiu recalled of an evening in April 2015. Colleagues had found something inside Kaspersky's own network that was, as he put it, "very big, very dangerous, and very, very serious."

The intruder was Duqu 2.0, a new generation of a Stuxnet cousin, using a zero-day in the Windows kernel. When Kaspersky went public that June, it said the attackers' main goal had been to spy on its technologies, research and internal processes.

The same platform, the team found, had been used against venues of the P5+1 talks on Iran's nuclear program and against an event marking the 70th anniversary of the liberation of Auschwitz-Birkenau.

Sponsored

A Cube on the Table

The pressure got personal. One evening Raiu came home at 7 p.m. to find a "decision cube," a desk toy that'd vanished from Kaspersky's Bucharest office, sitting in the middle of his table with the words "take a break" facing up.

"For a while, it turned my life upside down," he told Vice in 2015. "I understood it was serious. That my research annoyed some powerful people."

He kept working anyway. "Letting yourself be intimidated is a mistake," he said. "What we do is important."

Kaspersky Under Fire

Meanwhile the company itself was becoming the story. In September 2017 the US Department of Homeland Security ordered Kaspersky products off federal systems, and in June 2024 the Commerce Department banned sales of its software in the United States, citing the company's ties to Russia.

GReAT kept publishing. In June 2023 the team disclosed Operation Triangulation, a zero-click iMessage attack that'd been silently infecting iPhones on Kaspersky's own corporate network since 2019, including phones running iOS 15.7.

After GReAT

After 13 years at the helm, Raiu stepped down from GReAT. In October 2024 he sat for an episode billed as his "GReAT exit interview" on Three Buddy Problem, a weekly podcast he now co-hosts with Ryan Naraine and Juan Andres Guerrero-Saade, talking through why he left, the ethics of exposing certain operations and the "dark spots" where future-thinking APTs live.

He still turns up in the news whenever state hackers do. In March 2026, when a powerful iPhone exploit kit called Coruna surfaced, TechCrunch cited his observation about its bird-themed names, and Kaspersky later reported ties between Coruna and Operation Triangulation.

A month later, discussing Anthropic's Mythos model, he told Reuters that "a model like Mythos would have a field day finding exploits" in decades-old IBM banking systems, "just one example of ancient technologies powering the financial industry."

Sponsored

Costin Raiu: The Paleontologist of APTs

Raiu once titled a keynote "APT Paleontology in the age of cyber," and it fits. He spent his career digging up the bones of secret operations, several of them the work of nation-states by Kaspersky's own analysis, and he published anyway, through cash-paying strangers, a break-in at home and the slow freezing-out of his employer from the American market.

These days he does his digging out loud, on a weekly podcast and in the news, where the old cases keep coming back.

The schoolboy who wrote a cure for BadSectors never really stopped. He just moved on to much bigger networks.

QUOTE:

"Amateurs hack systems, professionals hack people."