HomeSecurityUS says it has dismantled Russian cyber espionage network Snake

US says it has dismantled Russian cyber espionage network Snake

The United States and its allies have dismantled the Snake cyberespionage system, which they said was used for years by Russian intelligence to spy on computers around the world, the Justice Department announced Tuesday.

US says it has dismantled Russian cyber espionage network Snake

In a separate report, the Cybersecurity and Infrastructure Security Agency (CISA) described the system, known as the “Snake” malware network, as “the most sophisticated cyberespionage tool” in the arsenal of the Federal Security Service (FSS). It has been used to monitor sensitive targets, including government networks, research facilities and journalists.

The Federal Security Service (FSB) had used Snake to access and steal international relations documents and other diplomatic communications from a NATO country, according to the Cybersecurity and Infrastructure Security Agency (CISA). CISA added that the Russian agency had used the tool to infect computers in more than 50 countries and within a range of American institutions, including educational institutions, small businesses, media organizations, government facilities, financial services, critical manufacturing and communications sectors.

“Through a high-tech operation that turned Russian malware against itself, U.S. law enforcement has neutralized one of Russia’s most sophisticated cyberespionage tools, which has been used for two decades to advance Russia’s authoritarian goals,” Lisa O. Monaco, deputy attorney general, said in a statement.

In a recently unsealed 33-page court filing by a federal judge in Brooklyn, cybersecurity agent Taylor Forry described how the effort, called Operation Medusa, would be carried out.

The Snake system, according to court documents, operated as a “peer-to-peer” network that connected infected computers around the world. Taking advantage of this, the FBI planned to infiltrate the system using an infected computer in the United States and bypass the code on each infected computer to “permanently disable” the network.

The US government has been scrutinizing malware related to Snake for nearly two decades, according to court records, which said an FSB unit known as Turla operated the network from Ryazan, Russia.

Although cybersecurity experts had identified and described the Snake network over the years, Turla kept it operational through upgrades and revisions.

Snake

Officials said the malware was difficult to remove from infected computer systems and that the hidden peer-to-peer network shreds and encrypts stolen data while secretly routing it through “numerous relay nodes scattered around the world” in a way that was difficult to detect.

The CISA report stated that Snake was designed in a way that allowed its operators to easily integrate new or upgraded components and that it ran on computers running Windows, Macintosh, and Linux operating systems.

The court documents also asked for a delay in notifying individuals whose computers would be accessed during the operation, saying it was imperative to coordinate the dismantling of “Snake” so the Russians could not reverse or mitigate it.

Source of information: nytimes.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS