US busts Russian cyber operation in dozens of countries

9 May 2023, 16:16

laptop
Russian invasion of Ukraine. Picture: PA

Prosecutors linked the spying operation to a unit of Russia’s Federal Security Service.

The US Justice Department says it has disrupted a long-running Russian cyber espionage campaign that stole sensitive information from computer networks in dozens of countries, including Nato members.

Prosecutors linked the spying operation to a unit of Russia’s Federal Security Service, or FSB, and accused the hackers of stealing documents from hundreds of computer systems belonging to governments of Nato members, an unidentified journalist for a US news organisation who reported on Russia, and other targets of interest to the Kremlin.

“For 20 years, the FSB has relied on the Snake malware to conduct cyber espionage against the United States and our allies — that ends today,” assistant attorney general Matthew Olsen, the head of the Justice Department’s National Security Division, said in a statement.

The specific targets were not named in court papers, but US officials described the espionage campaign as “consequential”, having extracted sensitive documents from Nato countries and government agencies and other organisations in the US.

The Russian operation relied on the malicious software known as Snake to infect computers, with hackers operating from what the Justice Department said was a known FSB facility in Ryazan, Russia.

US officials said they had been investigating Snake for about a decade and came to regard it as the most sophisticated malware implant used by the Russian government for espionage campaigns.

They said Turla, the FSB unit believed responsible for the malware, had refined and revised it multiple times to avoid being shut down.

The Justice Department, using a warrant this week from a federal judge in Brooklyn, launched what it said was a high-tech operation using a specialised tool called Perseus that caused the malware to effectively self-destruct.

Federal officials said they were confident that, based on the impact of its operation this week, the FSB would not be able to reconstitute the malware implant.

By Press Association

Latest World News

See more Latest World News

Storm damaged home

Tornadoes kill four people in Oklahoma

Israeli tanks

Biden and Netanyahu speak as ceasefire pressure grows on Israel and Hamas

Storm damage in Omaha

Tornadoes kill three in Oklahoma as state of emergency declared in 12 counties

Kharkiv damage

Ukrainian army chief reports tactical retreat in the east

Elon Musk meets Chinese Premier

Tesla founder Musk meets Chinese Premier as competitors show off new EVs

Ukrainians stabbed

Russian man arrested in Germany after two Ukrainians fatally stabbed

Fascists give salute

Dozens give fascist salute on anniversary of Mussolini’s execution

Damaged building

Energy infrastructure and hotel damaged in Russian drone attacks

Smoke from blast

Funeral held for 20 soldiers killed in munitions blast at Cambodian army base

Artist's impression of airport

Dubai’s ruler outlines plan to move airport to new £28bn facility

Iraqis

Passing of harsh anti-LGBT+ law in Iraq sparks diplomatic backlash

Tornado damage

Aerial photos reveal path of devastation after five killed in tornado in China

A worker wipes as visitors sit on a BYD Song Pro DM-i car model during the Auto China 2024 in Beijing

Tesla founder Musk visits China as competitors show off new electric vehicles

Rafah

Israel and Hamas urged to show ‘more commitment’ to ceasefire talks

Pope on boat

Pope urges inmates to seek ‘rebirth’ during prison visit

Joe Biden

Gaza protesters target White House dinner but Biden focuses on Trump