Sunday , August 23 2026

FBI Disables ‘Sophisticated’ Russian Snake Cyberspying Tool

U.S. officials announced on Tuesday that they had destroyed a worldwide network of compromised computers that Russian intelligence personnel had used to spy on the U.S. and its allies for over 20 years.

It has been reported that a branch of Russia’s Federal Security Service (FSB) stole classified material from hundreds of infiltrated computer networks in at least 50 countries by using malicious software known as Snake.

About thousands of leaked AWS keys Held Full Admin Rights

More than 9,300 AWS access keys that were made public from August 2022 to August 2026 are still active, says...
Read More
About thousands of leaked AWS keys Held Full Admin Rights

US Bank investigates LockBit’s Data Breach Claims

US Bank is looking into LockBit's claims about a breach and stolen data. The ransomware group says they will share...
Read More
US Bank investigates LockBit’s Data Breach Claims

Five new malware families actively targeting Asian Gov.t infra

Central Asian government agencies have been attacked in a cyber spy operation that used a small but different range of...
Read More
Five new malware families actively targeting Asian Gov.t infra

T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

T-Mobile’s cybersecurity team reportedly physically cut a network cable connecting compromised infrastructure to the outside world. According to Bloomberg, the move...
Read More
T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

Splunk has issued security fixes for 17 weaknesses in different apps and add-ons, such as Splunk MCP Server, Splunk AI...
Read More
Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

“Zombie Card” attack revels expired Visa card may be used for contactless payments

Security experts have shown that expired credit cards can still be used. A study from the University of Massachusetts Amherst,...
Read More
“Zombie Card” attack revels expired Visa card may be used for contactless payments

Critical Zimbra RCE Flaw Actively Exploited in the Wild

CERT Polska has alerted that bad actors are actively exploiting a security flaw in Zimbra Collaboration Suite to execute code...
Read More
Critical Zimbra RCE Flaw Actively Exploited in the Wild

Operation CameraSwarm
A single hacker compromise 1400+ Dahua camera worldwide 

Operation CameraSwarm compromised 14,500+ Dahua IP cameras mostly in Ukraine and Russia. The operation lasted for at least 35 days...
Read More
Operation CameraSwarm  A single hacker compromise 1400+ Dahua camera worldwide 

Cl0p Ransomware Listed 40+ Victims of PTC Windchill Campaign

The Cl0p ransomware group has listed over 40 organizations that they say they targeted in a recent attack. This attack...
Read More
Cl0p Ransomware Listed 40+ Victims of PTC Windchill Campaign

Oracle Issues 943 Security Patches, Including Critical WebLogic Flaw

Oracle has put out 943 new security updates in its August 2026 Critical Security Patch Update. These updates fix problems...
Read More
Oracle Issues 943 Security Patches, Including Critical WebLogic Flaw

According to the Russian government, the compromised computers belonged to NATO member governments, journalists, and other individuals of interest.

The information was sent back to Russia using hacked computers in the United States and elsewhere.

According to the Department of Justice, Snake is the “leading cyberespionage malware implant” used by the FSB.

“The Justice Department, together with our international partners, has dismantled a global network of malware-infected computers that the Russian government has used for nearly two decades to conduct cyber-espionage, including against our NATO allies,” said Attorney General Merrick Garland. In response to the Russian regime’s efforts to undermine U.S. and allied security, “continued strengthening of our collective defenses” will be implemented.”

The Justice Department announced that the FBI’s Operation MEDUSA successfully dissolved the Snake network with judicial approval. The operation used a tool developed by the FBI called PERSEUS to remove the Snake virus from infected machines.

Officials have stated that the department is collaborating with foreign governments in order to inform further people who have contracted the Snake sickness.

For more than twenty years, the FBI has monitored Snake and other malware programs, eventually creating the means to decrypt and decode communications involving Snake.

In a statement, Deputy Attorney General Lisa Monaco claimed that the takedown “has neutralized one of Russia’s most sophisticated cyber-espionage tools, used for two decades to advance Russia’s authoritarian objectives.”

“By combining this action with the release of the information victims need to protect themselves, the Justice Department continues to put victims at the center of our cybercrime work and take the fight to malicious cyber actors,” Monaco said.

The FSB Turla unit, according to court records unsealed on Tuesday, operated the Snake robot out of a known FSB base in the Russian city of Ryazan to carry out everyday espionage activities.

In order to maintain its status as “Turla’s most sophisticated long-term cyberespionage malware implant,” the unit has modified and changed the virus on multiple occasions, as stated by the Justice Department.

Conclusion

On Tuesday, the U.S. government disrupted a global network infected by Russia’s Federal Security Service (FSB) Snake virus. Snake, the “most sophisticated cyber espionage tool,” was created by Turla (aka Iron Hunter, Secret Blizzard, SUMMIT, Uroburos, Venomous Bear, and Waterbug), a Russian state-sponsored entity the U.S. government attributes to Center 16 of the FSB. The threat actor has previously focused on Europe, the Commonwealth of Independent States (CIS), and NATO countries.

Still, it has recently expanded to include Middle Eastern nations considered a threat to Russia-supported regional countries. “For nearly 20 years, this unit has used versions of the Snake malware to steal sensitive documents from hundreds of computer systems in at least 50 countries, which have belonged to North Atlantic Treaty Organization (NATO) member governments, journalists, and other targets of interest to the Russian Federation,” the Justice Department said. “After stealing these documents, Turla exfiltrated them through a covert network of unwitting Snake-compromised computers in the United States and worldwide.”

Check Also

Operation CameraSwarm

Operation CameraSwarm
A single hacker compromise 1400+ Dahua camera worldwide 

Operation CameraSwarm compromised 14,500+ Dahua IP cameras mostly in Ukraine and Russia. The operation lasted …