FBI says it has sabotaged hacking tool created by elite Russian spies collecting intel on Canada, NATO

The FBI has sabotaged a suite of malicious software used by elite Russian spies, U.S. authorities said on Tuesday.

In a joint cybersecurity advisory, the Canadian Centre for Cyber Security released an alert intended for IT professionals and “managers of notified organizations” warning them of a cyber espionage tool named “Snake.”

The malware “has been used globally by a malicious cyber actor with infrastructure being identified in over 50 countries across North America, South America, Europe, Africa, Asia and Australia,” the statement said.

“The purpose of Snake was to collect sensitive intelligence from high-priority targets such as government networks, research facilities and journalists,” it continued.

The centre joined security partners from U.S. agencies, the Australian Cyber Security Centre (ACSC), New Zealand’s National Cyber Security Centre (NCSC-NZ) and the United Kingdom’s National Cyber Security Centre (NCSC-UK).

Russian diplomats did not immediately return a message seeking comment. Moscow routinely denies carrying out cyberespionage operations.

U.S. officials spoke to journalists on Tuesday ahead of the news release on condition that they not be named. Similar announcements revealing Russia’s Federal Security Service (FSB) cyber disruption effort were made by security agencies in the U.K., Australia and New Zealand.

An official said the FSB spies behind the malware are part of a notorious hacking group tracked by the private sector and known as “Turla.”

The group has been active for two decades against a variety of NATO-aligned targets, U.S. government agencies and technology companies, a senior FBI official said.

Turla is widely considered one of the most sophisticated hacking teams studied by the security research community.

“They have persisted in the shadows by focusing on stealth and operational security,” said John Hultquist, vice president of threat analysis at U.S. cybersecurity company Mandiant. “They are one of the hardest targets we have.”

The U.S. government dubbed the disruption of Turla’s Snake malware “Operation Medusa.” The FBI and its partners identified where the hacking tool had been deployed across the internet and built a unique software “payload” to disrupt the hackers’ infrastructure.

The FBI relied on existing search warrant authorities to remotely access the Russian malicious program within victim networks in the U.S. and sever its connections.

The senior FBI official said the Bureau’s tool was designed only to communicate with the Russian spy program. “It speaks Snake, and communicates with Snake’s custom protocols” without accessing the victim’s personal files, the official said.

With additional files from Reuters

Post a Comment

Previous Post Next Post