Get all your news in one place.
100’s of premium titles.
One app.
Start reading
Reuters
Reuters
World
By Raphael Satter and Christopher Bing

FBI says it has sabotaged hacking tool created by elite Russian spies

FILE PHOTO: A Russian flag is seen on the laptop screen in front of a computer screen on which cyber code is displayed, in this illustration picture. REUTERS/Kacper Pempel/Illustration

The FBI has sabotaged a suite of malicious software used by elite Russian spies, U.S. authorities said on Tuesday, providing a glimpse of the digital tug-of-war between two cyber superpowers.

Senior law enforcement officials said FBI technical experts had identified and disabled malware wielded by Russia's FSB security service against an undisclosed number of American computers, a move they hoped would deal a death blow to one of Russia's leading cyber spying programs.

"We assess this as being their premier espionage tool," one of the U.S. officials told journalists ahead of the release. He said Washington hoped the operation would "eradicate it from the virtual battlefield."

The official said the FSB spies behind the malware, known as Snake, are part of a notorious hacking group tracked by the private sector and known as "Turla."

The group has been active for two decades against a variety of NATO-aligned targets, U.S. government agencies and technology companies, a senior FBI official said.

Russian diplomats did not immediately return a message seeking comment. Moscow routinely denies carrying out cyberespionage operations.

U.S. officials spoke to journalists on Tuesday ahead of the news release on condition that they not be named. Similar announcements, revealing the FSB cyber disruption effort, were made by security agencies in the UK, Canada, Australia and New Zealand.

Turla is widely considered one of the most sophisticated hacking teams studied by the security research community.

"They have persisted in the shadows by focusing on stealth and operational security," said John Hultquist, vice president of threat analysis at U.S. cybersecurity company Mandiant. "They are one of the hardest targets we have."

The U.S. government dubbed the disruption of Turla's Snake malware "Operation Medusa." The FBI and its partners identified where the hacking tool had been deployed across the internet and built a unique software "payload" to disrupt the hackers' infrastructure.

The FBI relied on existing search warrant authorities to remotely access the Russian malicious program within victim networks in the U.S. and sever its connections.

The senior FBI official said the Bureau's tool was designed only to communicate with the Russian spy program. "It speaks Snake, and communicates with Snake's custom protocols" without accessing the victim's personal files, the official said.

(Reporting by Raphael Satter; Editing by Chizu Nomiyama and David Gregorio)

Sign up to read this article
Read news from 100’s of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.