Russia-owned Snake Malware disrupted by DoJ

GEAR CHECK: Our readers don't just follow the news - they stay ready. Featured gear from this story is below.

Staff Writer

The Justice Department has announced the successful completion of a court-authorized operation, known as MEDUSA, to disrupt a global peer-to-peer network of computers compromised by “Snake,” a sophisticated Russian-owned malware.

Government attributes to a unit within Center 16 of the Federal Security Service of the Russian Federation (FSB).

The operation disabled Turla’s Snake malware on compromised computers using an FBI-created tool named PERSEUS, which caused the malware to overwrite its vital components. The operation was executed by the FBI with a search warrant issued by U.S. Magistrate Judge Cheryl L. Pollak for the Eastern District of New York.

<blockquote class="twitter-tweet"><p lang="en" dir="ltr">The Department of Justice (DOJ) has announced the takedown of a global malware known as &quot;Snake&quot;. The operation known as “MEDUSA” was conducted in joint cooperation with international law enforcement agencies <a href="https://twitter.com/hashtag/cyber?src=hash&amp;ref_src=twsrc%5Etfw">#cyber</a> <a href="https://twitter.com/hashtag/cybercrime?src=hash&amp;ref_src=twsrc%5Etfw">#cybercrime</a> <a href="https://twitter.com/hashtag/malware?src=hash&amp;ref_src=twsrc%5Etfw">#malware</a> <a href="https://twitter.com/hashtag/doj?src=hash&amp;ref_src=twsrc%5Etfw">#doj</a><a href="https://t.co/Je0R63nuSM">https://t.co/Je0R63nuSM</a> <a href="https://t.co/DBKe3LNvII">pic.twitter.com/DBKe3LNvII</a></p>&mdash; Cyber Statesman (@cyberstatesman) <a href="https://twitter.com/cyberstatesman/status/1656304867839815680?ref_src=twsrc%5Etfw">May 10, 2023</a></blockquote> <script async src="https://platform.twitter.com/widgets.js" charset="utf-8"></script>

The FBI is engaging with local authorities to provide notice of Snake infections and remediation guidance to victims outside the United States. Attorney General Merrick B. Garland stated that the Justice Department, along with its international partners, has dismantled a global network of malware-infected computers that the Russian government has used for nearly two decades to conduct cyber espionage, including against its NATO allies.

The Deputy Attorney General, Lisa O. Monaco, added that the Justice Department continues to put victims at the center of its cybercrime work and takes the fight against malicious cyber actors by combining the action with the release of information victims need to protect themselves.

The Justice Department’s National Security Division’s Assistant Attorney General, Matthew G. Olsen, stated that the FSB has relied on the Snake malware to conduct cyber-espionage against the United States and its allies for twenty years, which ends today. He added that the Justice Department would use every weapon in its arsenal to combat Russia’s malicious cyber activity. U.S. Attorney Breon Peace for the Eastern District of New York noted that the FBI’s court-authorized remote search and remediation demonstrated the office’s and its partners’ commitment to using all available tools to protect the American people.

The FBI, along with other government agencies and private sector entities, collaborated to disrupt the Snake malware network, which was led by the FBI New York Field Office and the Cyber Division. The Criminal Division’s Computer Crime and Intellectual Property Section assisted in the operation, and private sector entities were instrumental in the successful outcome by allowing the FBI to monitor Snake communications on their systems.

Snake has been the subject of several cybersecurity industry reports, but Turla has applied numerous upgrades and revisions and selectively deployed it to ensure that it remains its most sophisticated long-term cyberespionage malware implant. The FBI observed Snake persist on particular computers despite a victim’s efforts to remediate the compromise. The Turla unit uses the Snake network to route data exfiltrated from target systems through numerous relay nodes scattered worldwide back to its operators in Russia.

 

You may also like

Blog

A routine campaign stops at an Ohio county fair suddenly turned into a security emergency when an armed man allegedly forced his way through a crowd and charged toward Democratic gubernatorial candidate Amy Acton.
The U.S.-Iran war entered a dangerous new phase on September 5 when Iran fired ballistic missiles at two American warships, prompting the United States to strike three Iranian oil tankers in a rapid military and economic retaliation.
A new dark-web marketplace may have exposed the identities of more than 153 million people across the United States and Canada, with hackers reportedly offering digital copies of government-issued IDs for sale.
A wedding celebration in southern Iran turned deadly on September 1 after a U.S. strike reportedly sent missile fragments into a home where dozens of people had gathered, killing at least five people and injuring more than 60.
A 22-year-old college student went to the wrong house in the middle of the night. Minutes later, he was dead after being shot twice by a police officer who had responded to a 911 call about a possible break-in.

Like This Story? Check Out What Our Community Is Buying

Our best sellers are designed for real-world use - not hype.

View Best Sellers