Kaspersky said it was able to get an insight into the hackers by taking over some of their servers and decoding their log files, which basically serve as a running tally of which files are being stolen from whom. Kaspersky named a series of Japanese and South Korean firms as being among the group's targets, but it did not specify whether they actually had data stolen.
Kaspersky gave the group the name "Icefog," after a line of code found on one of the group's servers. As for who's behind Icefog, some mystery remains. Raiu said the attackers used Chinese characters and, in one case, appear to have inadvertently left their names in the code of one of the component pieces of their software.
But he said the group appeared to fluent in Korean and Japanese and said forensic data gathered by Kaspersky pointed to a cross-border outfit operating out of China, South Korea, and Japan. If true, it would be an interesting wrinkle given that the three countries are often thought of as commercial rivals.
"It's definitely unusual," he said.