Categories: Technology

The FBI is letting Putin’s elite hackers run into the open knife

The FBI has sabotaged and disabled Russia’s most powerful cyber-espionage tool. It is said to have spied on targets in 50 countries. Operation Medusa was preceded by eight years of research.
Oliver Wietlisbach

The FBI has sabotaged and disabled hacking software used by elite Russian spies against Western government agencies and businesses. It is the infamous Snake malware, a cyber-espionage toolkit that has been controlled by the Russian FSB hacker group Turla for nearly two decades. Senior US law enforcement officials announced this on Tuesday.

The removal of the malware was part of the so-called Operation Medusa, which aims to deal the final blow to one of Russia’s leading cyber-espionage programs. “We consider this your primary espionage tool,” said one of the officials. It is hoped that the blow will “wipe the Turla spy group from the virtual battlefield”.

Turla is widely regarded as one of the most advanced hacking groups. An FBI official said the group has been active for two decades against various targets within NATO, US government agencies and technology companies. The group, which the United States says is controlled by the Russian domestic secret service FSB, operated in secrecy for years.

How the US caught up to Putin’s elite hackers

According to court documents, the FBI and intelligence agencies in the US, UK, Canada, Australia and New Zealand have been investigating the Russian Snake malware and its operation for at least eight years, since it was found on the networks of several US organizations in 2015. the cyber experts analyzed how the well-camouflaged malware comes home encrypted and how the hacker group unnoticed downloads the data from infected computer systems.

US officials have described Snake as the FSB’s “most sophisticated cyber-espionage tool”. In addition to Windows, it can also infiltrate Linux and macOS. Russia’s domestic intelligence agency used the malware to steal sensitive information from high-level targets, such as government networks, research institutions and journalists.

Once on a computer system, Snake loads additional software modules that allow hackers to exfiltrate confidential data unnoticed through encrypted connections.

The computer systems infected with Snake were not only misused to collect data, but also involuntarily acted as a proxy server or botnet, which was used to hide data traffic from other Snake attacks.

FBI sure: hackers come from Russia

Due to the skilled and careful approach of the hackers, the cyber attacks were largely invisible for many years. But when the group’s researchers found out in 2015, they didn’t just manage to expose other Snake-infected systems. It was even possible to “locate the malware’s main operations center,” as cybersecurity news service Risky Biz News reports. Accordingly, Snake could be linked to an FSB facility in Ryazan, a city 200 kilometers southeast of Moscow.

The FBI and its partners have now succeeded in paralyzing the hackers’ infrastructure with their own software. The FBI relied on existing search warrants to remotely access the Russian malware on victims’ networks in the US and cut ties with the hackers in Russia.

A senior FBI official told Reuters that the FBI’s tool was designed solely to bring down Russia’s spy program. It does this without access to the victim’s personal information.

According to authorities, the malware has been found on systems in more than 50 countries. Although the FBI has shut down Snake and authorities in other countries are now being advised on how to remove Snake, the risk of infected computer systems remains high. The FBI warns that the hackers can almost always use a keylogger on infected systems and come back with the stolen credentials, as long as the associated passwords have not been changed.

There was initially no comment from Russia. The Moscow leadership denies regular involvement in cyber espionage.

Oliver Wietlisbach

Source: Watson

Share
Published by
Ella

Recent Posts

Terror suspect Chechen ‘hanged himself’ in Russian custody Egyptian President al-Sisi has been sworn in for a third term

On the same day of the terrorist attack on the Krokus City Hall in Moscow,…

1 year ago

Locals demand tourist tax for Tenerife: “Like a cancer consuming the island”

class="sc-cffd1e67-0 iQNQmc">1/4Residents of Tenerife have had enough of noisy and dirty tourists.It's too loud, the…

1 year ago

Agreement reached: this is how much Tuchel will receive for his departure from Bayern

class="sc-cffd1e67-0 iQNQmc">1/7Packing his things in Munich in the summer: Thomas Tuchel.After just over a year,…

1 year ago

Worst earthquake in 25 years in Taiwan +++ Number of deaths increased Is Russia running out of tanks? Now ‘Chinese coffins’ are used

At least seven people have been killed and 57 injured in severe earthquakes in the…

1 year ago

Now the moon should also have its own time (and its own clocks). These 11 photos and videos show just how intense the Taiwan earthquake was

The American space agency NASA would establish a uniform lunar time on behalf of the…

1 year ago

This is how the Swiss experienced the earthquake in Taiwan: “I saw a crack in the wall”

class="sc-cffd1e67-0 iQNQmc">1/8Bode Obwegeser was surprised by the earthquake while he was sleeping. “It was a…

1 year ago