No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

US, partners dismantle malware network used in 20-year Russian spy campaign

May 10, 2023
in Protection
0
US, partners dismantle malware network used in 20-year Russian spy campaign



The Department of Justice announced May 9 that the FBI and law enforcement partners around the world have hacked and disrupted a malware-compromised peer-to-peer network used by “Turla,” an espionage-minded hacking group tied to the Federal Security Service (FSB) of the Russian government.

Different variants of the malware — which the U.S. government calls “Snake” — were used by Russian hackers to compromise systems and pilfer data from hundreds of computers across 50 countries over the past two decades, including the United States.

The federal and law enforcement operation included the FBI obtaining a court order from the Eastern District of New York to use a hacking tool called PERSEUS, which is designed to send out commands that forced Snake malware to overwrite itself on infected devices.

The action was revealed after the government partially unsealed parts of the search warrant used to seize and examine a number of Snake-infected devices. In a statement, Attorney General Merrick Garland said the operation has “dismantled” the espionage campaign that officials said was ongoing for more than 20 years.

“The Justice Department, together with our international partners, has dismantled a global network of malware-infected computers that the Russian government has used for nearly two decades to conduct cyber-espionage, including against our NATO allies,” said Garland. “We will continue to strengthen our collective defenses against the Russian regime’s destabilizing efforts to undermine the security of the United States and our allies.”

The malware implant is designed to persist on a victim system “indefinitely,” and the FBI said it observed numerous instances where victims were unable to remove the infection, even after remediation. The bureau is contacting local governments and law enforcement agencies in other countries to notify affected victims and offer guidance on how to remove the implant.

According to a parallel cybersecurity advisory released the same day by agencies in the U.S., UK, Canada and Australia, the Snake implant is used by Center 16, a unit within the FSB specifically to conduct “long-term intelligence collection on sensitive targets.” Such targets include government networks, NATO, research facilities and journalists, and the tool has been used in dozens of countries on nearly continent around the world.

“Within the United States, the FSB has victimized industries, including education, small businesses, and media organizations, as well as critical infrastructure sectors including government facilities, financial services, critical manufacturing, and communications,” the advisory states.

John Hultquist, head of Mandiant Threat Intelligence at Google Cloud, called Turla “one of the oldest intrusion groups we track” with a record of espionage-minded hacking campaigns that date back to at least the 1990s.

Hultquist highlighted a number of incidents carried out by the group that have become public, such as the Agent.BTZ campaign — a computer worm that used USB flash drives to infect classified and unclassified networks at U.S. Central Command — and Moonlight Maze — an espionage campaign that spanned the 1990s and compromised the networks of the Department of Defense, NASA, the Department of Energy, defense contractors and other parties.

Turla heavily invested in operational security and Hultquist said those incidents are dwarfed by “a breadth of activity that goes unnoticed.”

“They are focused on the classic targets of espionage: government, military and the defense sector; and their activity is characterized by a reliably quiet assault on these targets that rarely draws attention to themselves,” he said in a statement.

The coordinated campaign to disrupt the network marks the latest example of efforts by U.S. and international law enforcement to target and dismantle the tools and infrastructure used by state and criminal hacking groups — through court orders, raids and, at times, hacking back — and is a goal that has become increasingly important to policymakers as they look to affect hacking operations when more traditional arrests and indictments aren’t realistic.

Over the past two years, the Department of Justice has overseen seizures and takedowns of infrastructure used by the Hive ransomware group and other criminal operations, while also using court orders to delete web shells set up and exploited by Chinese hackers and other parties in Microsoft Exchange servers in 2021.

The action was announced a day after the Justice Department revealed it seized more than a dozen “booter” services used by criminal distributed-denial-of-service operations.

Editorial Team

Editorial Team

Related Posts

My Favorite Portable Projector Is $130 Off During Amazon's Early Big Spring Sale
Protection

My Favorite Portable Projector Is $130 Off During Amazon’s Early Big Spring Sale

March 20, 2026
This Massive Data Breach Leaked 2.7 Million Social Security Numbers
Protection

This Massive Data Breach Leaked 2.7 Million Social Security Numbers

March 20, 2026
Six Strength Training 'Rules' You Can Safely Ignore, According to the ACSM
Protection

Six Strength Training ‘Rules’ You Can Safely Ignore, According to the ACSM

March 20, 2026
YouTube Wants Your Help Identifying AI Slop on Its Platform
Protection

YouTube Wants Your Help Identifying AI Slop on Its Platform

March 20, 2026
Google Just Made Four Big Upgrades to Android Gaming on Your Windows PC
Protection

Google Just Made Four Big Upgrades to Android Gaming on Your Windows PC

March 20, 2026
Here’s How Google’s ‘Safer’ Sideloading Works on Android
Protection

Here’s How Google’s ‘Safer’ Sideloading Works on Android

March 20, 2026
Load More
Next Post
Joe Biden urges Republicans to drop default threat in debt ceiling talks

Joe Biden urges Republicans to drop default threat in debt ceiling talks

Popular News

  • Josh Garber

    How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • Analysis-New Zealand struggles to regain economic mojo without housing recovery

    0 shares
    Share 0 Tweet 0
  • When You Buy a Pair of These Bose Earbuds, You Can Get a Second Pair Free

    0 shares
    Share 0 Tweet 0
  • The Death of the Résumé: How Agentic AI & Skills-Based Hiring Are Rewriting the Rules in 2026

    0 shares
    Share 0 Tweet 0
  • You Can Get This Highly Rated Smartphone Gimbal for $99 Right Now

    0 shares
    Share 0 Tweet 0

Latest News

BTC Performance Driven By Individuals While Central Banks Drive Gold Price

BTC Performance Driven By Individuals While Central Banks Drive Gold Price

March 22, 2026
0

The divergence between gold and Bitcoin (BTC) in 2026 can be explained by two distinct segments of buyers, according to...

Oil prices rise after US, Iran threaten to hit energy targets in the Middle East

Oil prices rise after US, Iran threaten to hit energy targets in the Middle East

March 22, 2026
0

Oil prices rise after US, Iran threaten to hit energy targets in the Middle East

U.S. stock futures sink as Trump and Iran trade threats against civilian infrastructure

U.S. stock futures sink as Trump and Iran trade threats against civilian infrastructure

March 22, 2026
0

U.S. stock-index futures fell on Sunday, as new threats of escalation from both President Donald Trump and Iran threatened to...

Ripple eyes $2 with new legal developments; RCO Finance is set to accelerate

David Schwartz joins XRP-Solana meme war on X

March 22, 2026
0

Ripple’s CTO emeritus David Schwartz recently engaged in an interesting exchange on X, responding to a post about XRP with...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.