Tuesday , December 24 2024

FBI Disables ‘Sophisticated’ Russian Snake Cyberspying Tool

U.S. officials announced on Tuesday that they had destroyed a worldwide network of compromised computers that Russian intelligence personnel had used to spy on the U.S. and its allies for over 20 years.

It has been reported that a branch of Russia’s Federal Security Service (FSB) stole classified material from hundreds of infiltrated computer networks in at least 50 countries by using malicious software known as Snake.

New G-Door Vul Allow Hackers Bypass Microsoft 365 Security With Google Docs

A newly discovered vulnerability called "G-Door" enables malicious actors to bypass Microsoft 365 security by exploiting unmanaged Google Docs accounts....
Read More
New G-Door Vul Allow Hackers Bypass Microsoft 365 Security With Google Docs

CVE-2024-53961
Adobe alerts of critical ColdFusion bug with PoC exploit available

Adobe has issued urgent security updates for ColdFusion versions 2023 and 2021 to fix a critical vulnerability (CVE-2024-53961). This flaw...
Read More
CVE-2024-53961  Adobe alerts of critical ColdFusion bug with PoC exploit available

Splunk targets Bangladeshi market: Investing in local talent

Splunk, a unified security and observability platform turn its focuses on Bangladeshi market. On Monday (23 December) Splunk's local partner...
Read More
Splunk targets Bangladeshi market: Investing in local talent

Critical PHP Zero-Day Vulnerability found in Craft CMS To Gain RCE

A major security flaw in Craft CMS, a popular PHP content management system, has been found, enabling unauthenticated remote code...
Read More
Critical PHP Zero-Day Vulnerability found in Craft CMS To Gain RCE

For US$2.6bn, Mastercard acquires threat intelligence firm Recorded Future

Mastercard has completed its acquisition of Recorded Future, an AI-based threat intelligence provider. Mastercard has acquired the company for $2.65...
Read More
For US$2.6bn, Mastercard acquires threat intelligence firm Recorded Future

Eight New ICS Advisories released by CISA

CISA has released eight advisories on vulnerabilities in Industrial Control Systems (ICS). These vulnerabilities affect essential software and hardware in...
Read More
Eight New ICS Advisories released by CISA

Authority Denies
Hacker claim ransomware attack on Indonesia’s state bank BRI

Bank Rakyat Indonesia (BRI), the largest state bank by assets, has assured customers that their data and funds are secure...
Read More
Authority Denies  Hacker claim ransomware attack on Indonesia’s state bank BRI

London-based company “Builder.ai” reportedly exposed 1.2 TB data

Cybersecurity researcher Jeremiah Fowler reported to Website Planet that he found a non-password-protected 1.2 TB dataset containing over 3 million...
Read More
London-based company “Builder.ai” reportedly exposed 1.2 TB data

(CVE-2024-12727, CVE-2024-12728, CVE-2024-12729)
Sophos resolved 3 critical vulnerabilities in Firewall

Sophos has fixed three separate security vulnerabilities in Sophos Firewall.  The vulnerabilities CVE-2024-12727, CVE-2024-12728, and CVE-2024-12729 present major risks, such...
Read More
(CVE-2024-12727, CVE-2024-12728, CVE-2024-12729)  Sophos resolved 3 critical vulnerabilities in Firewall

“Workshop on Cybersecurity Awareness and Needs Analysis” held at BBTA

A time-demanding workshop on "Cybersecurity Awareness and Needs Analysis" was held on Thursday (December 19) at Bangladesh Bank Training Academy...
Read More
“Workshop on Cybersecurity Awareness and Needs Analysis” held at BBTA

According to the Russian government, the compromised computers belonged to NATO member governments, journalists, and other individuals of interest.

The information was sent back to Russia using hacked computers in the United States and elsewhere.

According to the Department of Justice, Snake is the “leading cyberespionage malware implant” used by the FSB.

“The Justice Department, together with our international partners, has dismantled a global network of malware-infected computers that the Russian government has used for nearly two decades to conduct cyber-espionage, including against our NATO allies,” said Attorney General Merrick Garland. In response to the Russian regime’s efforts to undermine U.S. and allied security, “continued strengthening of our collective defenses” will be implemented.”

The Justice Department announced that the FBI’s Operation MEDUSA successfully dissolved the Snake network with judicial approval. The operation used a tool developed by the FBI called PERSEUS to remove the Snake virus from infected machines.

Officials have stated that the department is collaborating with foreign governments in order to inform further people who have contracted the Snake sickness.

For more than twenty years, the FBI has monitored Snake and other malware programs, eventually creating the means to decrypt and decode communications involving Snake.

In a statement, Deputy Attorney General Lisa Monaco claimed that the takedown “has neutralized one of Russia’s most sophisticated cyber-espionage tools, used for two decades to advance Russia’s authoritarian objectives.”

“By combining this action with the release of the information victims need to protect themselves, the Justice Department continues to put victims at the center of our cybercrime work and take the fight to malicious cyber actors,” Monaco said.

The FSB Turla unit, according to court records unsealed on Tuesday, operated the Snake robot out of a known FSB base in the Russian city of Ryazan to carry out everyday espionage activities.

In order to maintain its status as “Turla’s most sophisticated long-term cyberespionage malware implant,” the unit has modified and changed the virus on multiple occasions, as stated by the Justice Department.

Conclusion

On Tuesday, the U.S. government disrupted a global network infected by Russia’s Federal Security Service (FSB) Snake virus. Snake, the “most sophisticated cyber espionage tool,” was created by Turla (aka Iron Hunter, Secret Blizzard, SUMMIT, Uroburos, Venomous Bear, and Waterbug), a Russian state-sponsored entity the U.S. government attributes to Center 16 of the FSB. The threat actor has previously focused on Europe, the Commonwealth of Independent States (CIS), and NATO countries.

Still, it has recently expanded to include Middle Eastern nations considered a threat to Russia-supported regional countries. “For nearly 20 years, this unit has used versions of the Snake malware to steal sensitive documents from hundreds of computer systems in at least 50 countries, which have belonged to North Atlantic Treaty Organization (NATO) member governments, journalists, and other targets of interest to the Russian Federation,” the Justice Department said. “After stealing these documents, Turla exfiltrated them through a covert network of unwitting Snake-compromised computers in the United States and worldwide.”

Check Also

sonicwall

Over 25K SonicWall VPN Firewalls exposed to critical flaws

More than 25,000 SonicWall SSL VPN devices are vulnerable to critical flaws, with 20,000 running …

Leave a Reply

Your email address will not be published. Required fields are marked *