index

Russia-owned Snake Malware disrupted by DoJ

GEAR CHECK: Our readers don't just follow the news - they stay ready. Featured gear from this story is below.

Staff Writer

The Justice Department has announced the successful completion of a court-authorized operation, known as MEDUSA, to disrupt a global peer-to-peer network of computers compromised by “Snake,” a sophisticated Russian-owned malware.

Government attributes to a unit within Center 16 of the Federal Security Service of the Russian Federation (FSB).

The operation disabled Turla’s Snake malware on compromised computers using an FBI-created tool named PERSEUS, which caused the malware to overwrite its vital components. The operation was executed by the FBI with a search warrant issued by U.S. Magistrate Judge Cheryl L. Pollak for the Eastern District of New York.

<blockquote class="twitter-tweet"><p lang="en" dir="ltr">The Department of Justice (DOJ) has announced the takedown of a global malware known as &quot;Snake&quot;. The operation known as “MEDUSA” was conducted in joint cooperation with international law enforcement agencies <a href="https://twitter.com/hashtag/cyber?src=hash&amp;ref_src=twsrc%5Etfw">#cyber</a> <a href="https://twitter.com/hashtag/cybercrime?src=hash&amp;ref_src=twsrc%5Etfw">#cybercrime</a> <a href="https://twitter.com/hashtag/malware?src=hash&amp;ref_src=twsrc%5Etfw">#malware</a> <a href="https://twitter.com/hashtag/doj?src=hash&amp;ref_src=twsrc%5Etfw">#doj</a><a href="https://t.co/Je0R63nuSM">https://t.co/Je0R63nuSM</a> <a href="https://t.co/DBKe3LNvII">pic.twitter.com/DBKe3LNvII</a></p>&mdash; Cyber Statesman (@cyberstatesman) <a href="https://twitter.com/cyberstatesman/status/1656304867839815680?ref_src=twsrc%5Etfw">May 10, 2023</a></blockquote> <script async src="https://platform.twitter.com/widgets.js" charset="utf-8"></script>

The FBI is engaging with local authorities to provide notice of Snake infections and remediation guidance to victims outside the United States. Attorney General Merrick B. Garland stated that the Justice Department, along with its international partners, has dismantled a global network of malware-infected computers that the Russian government has used for nearly two decades to conduct cyber espionage, including against its NATO allies.

The Deputy Attorney General, Lisa O. Monaco, added that the Justice Department continues to put victims at the center of its cybercrime work and takes the fight against malicious cyber actors by combining the action with the release of information victims need to protect themselves.

The Justice Department’s National Security Division’s Assistant Attorney General, Matthew G. Olsen, stated that the FSB has relied on the Snake malware to conduct cyber-espionage against the United States and its allies for twenty years, which ends today. He added that the Justice Department would use every weapon in its arsenal to combat Russia’s malicious cyber activity. U.S. Attorney Breon Peace for the Eastern District of New York noted that the FBI’s court-authorized remote search and remediation demonstrated the office’s and its partners’ commitment to using all available tools to protect the American people.

The FBI, along with other government agencies and private sector entities, collaborated to disrupt the Snake malware network, which was led by the FBI New York Field Office and the Cyber Division. The Criminal Division’s Computer Crime and Intellectual Property Section assisted in the operation, and private sector entities were instrumental in the successful outcome by allowing the FBI to monitor Snake communications on their systems.

Snake has been the subject of several cybersecurity industry reports, but Turla has applied numerous upgrades and revisions and selectively deployed it to ensure that it remains its most sophisticated long-term cyberespionage malware implant. The FBI observed Snake persist on particular computers despite a victim’s efforts to remediate the compromise. The Turla unit uses the Snake network to route data exfiltrated from target systems through numerous relay nodes scattered worldwide back to its operators in Russia.

 

You may also like

Blog

A Palatka Goodwill store was evacuated after employees discovered a live grenade among donated items, prompting a bomb squad response and a public safety warning from police.
The U.S. Army has taken delivery of its first M1E3 Abrams tank prototype, launching an accelerated testing and acquisition effort aimed at rapidly modernizing armored forces.
A Pentagon AI chatbot has drawn attention after labeling a hypothetical follow-up airstrike on survivors at sea as illegal, as the Defense Department rolls out its new GenAI platform to military personnel.
Syria has arrested five suspects after a deadly ambush near Palmyra killed three Americans, as the US vows strong retaliation while investigations continue into possible ISIL links.
A Georgia woman is recovering from severe burns after being attacked with a corrosive chemical during an evening walk in Savannah’s Forsyth Park, as police and the FBI search for those with information.

Like This Story? Check Out What Our Community Is Buying

Our best sellers are designed for real-world use - not hype.

View Best Sellers