The FBI announced that it has wiped out one of Russia’s most advanced-level malware tools, used to spy on computers around the world for the last two decades.
The agency carried out a joint operation with international allies codenamed MEDUSA, targeting “Snake” malware used by the Federal Security Services of the Russian Federation (FSB), the Department of Justice announced Tuesday.
The Kremlin-backed Snake was used to swipe sensitive documents from hundreds of devices belonging to government officials, journalists, and other targets in at least 50 countries — many of those members of NATO, the department said.
In a separate advisory, the Cybersecurity & Infrastructure Security Agency (CISA) noted that Snake was the “most sophisticated cyberespionage tool” the Russian FSB had at its disposal.
Cybersecurity experts and court documents say the FSB spies behind Snake are part of a hacking group known as “Turla,” which has also created another advanced Russian malware strain of the same name.
FBI Tool PERSEUS: Mongoose That Killed the Snake
The modular, multi-purpose Snake malware operates via a hidden peer-to-peer (P2P) network of infected computers worldwide, with several of these systems serving as relays to hide criminal traffic — similar to how Tor‘s anonymous system works. Snake also uses custom, encrypted and fragmented protocols to avoid detection, the CISA advisory said.
The malware can stay hidden on a system even if rebooted, hide itself, employ custom communications protocols, move laterally once inside a target network to access more data and systems, and even key log and swipe account logins.
According to the advisory, a court-authorized FBI tool dubbed PERSEUS successfully caused Snake to overwrite itself, effectively disabling the malware from the core and causing it to eat its own tail.
This was done by tricking the malware into executing a fake command that mimicked a legitimate FSB command, the Department of Justice explained.
How Users and Organizations Can Defend Against Snake, Copycat Malware
Though Snake has been disrupted, this does not mean hacking groups will not relaunch the malware in a new form, yet another reason why the U.S. has committed to bolstering global cyber resilience with its allies.
“The Justice Department will use every weapon in our arsenal to combat Russia’s malicious cyber activity, including neutralizing malware through high-tech operations, making [innovative] use of legal authorities, and working with international allies and private sector partners to amplify our collective impact,” U.S. Assistant Attorney General Matt Olsen stated on Tuesday.
The advisory is designed to help organizations around the world understand and defend against Snake, suggesting that, among other things, they first harden external-facing systems.
Since the malware is typically deployed to external-facing infrastructure nodes on networks, all internet users, and especially organizations, need to ensure cybersecurity basics. This includes making sure that software and systems are up to date with the latest security patches, and that strong passwords are used in conjunction with multi-factor and novel Passkey authentication.
More advanced suggestions from the advisory for organizations include implementing network segmentation, conducting regular security awareness training, monitoring network traffic, and deploying endpoint protection.
If an organization suspects it has been compromised by Snake or any other malware, it is important to act swiftly and follow incident response mitigation procedures.
Individuals and organizations alike should peruse our latest premium antivirus write-ups to see what works best on their systems.
