News: 1683664084

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

FBI-led Op Medusa slays NATO-bothering Russian military malware network

(2023/05/09)


The FBI has cut off a network of Kremlin-controlled computers used to spread the Snake malware which, according to the Feds, has been used by Russia's FSB to steal sensitive documents from NATO members for almost two decades.

Turla, the FSB-backed cyberspy group, has used versions of the Snake malware to steal data from hundreds of computer systems belonging to governments, journalists, and other targets of interest in at least 50 countries, according to the US Justice Department. After identifying and stealing sensitive files on victims' devices, Turla exfiltrated them through a covert network of unwitting Snake-compromised computers in the US.

In effect, Snake can infect Windows, Linux, and macOS systems, and use those network nodes to pass data stolen from victims along to the software nasty's Russian spymasters. The NSA published a technical overview of the code [1]here and [2]here [PDF].

[3]

"To obfuscate communications between the Snake-compromised computers that comprise the Snake network, the nature of the data stolen by the FSB and the identity of the FSB as the attacker, communications between Snake implants on compromised computers are encrypted, fragmented, and sent using customized methodologies built atop common network protocols," according to US prosecutors in court documents

[4]PDF

.

[5]

[6]

"As a result, Snake communications are difficult to distinguish from legitimate victim network traffic, and the data payloads are impossible to decrypt and interpret without software specifically designed to process the implant's custom protocols," the affidavit continues.

As part of the so-called Operation Medusa, announced today, the Feds obtained a warrant

[7]PDF

to remotely access eight computers in the US that Snake had infected, and then overwrite and terminate the malware running on those machines.

[8]

"Through a high-tech operation that turned Russian malware against itself, US law enforcement has neutralized one of Russia's most sophisticated cyber-espionage tools, used for two decades to advance Russia's authoritarian objectives," Deputy Attorney General Lisa Monaco said in a [9]statement .

According to the court documents, the FBI had been monitoring the malware's activity on infected computers in America — with their owners' permission, we're told. Agents were able to study the code and develop a technique that mimics Snake's session authentication protocol to trick another computer on the network into communicating with it.

[10]288 arrested in multinational Monopoly Market takedown

[11]Cops put the squeeze on Genesis crime souk denizens, not just the admins this time

[12]Russia-pushed UN Cybercrime Treaty may rewrite global law. It's ... not great

[13]FBI smokes ransomware Hive after secretly buzzing around gang's network for months

The FBI decided to name this tool Perseus, and after it establishes communication sessions with the Snake malware on a device, issues commands that causes the malicious implant to disable itself by overwriting key code components, without affecting the host computer or any legitimate applications.

As many of the malware's victims are located outside the US, the FBI says it's engaging with local authorities to provide notice of Snake infections and offer remediation guidance.

Operation Medusa is the latest in a series of high-profile actions this month that Uncle Sam and friends have taken in the past few months to disrupt cybercrime.

[14]

Yesterday, the DOJ said it has [15]seized 13 internet domains selling distributed-denial-of-service attacks.

And earlier this month, US and European law enforcement arrested 288 people who were allegedly selling opioids on the now-shuttered [16]Monopoly Market dark web drug trafficking marketplace. ®

Get our [17]Tech Resources



[1] https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/3389044/us-agencies-and-allies-partner-to-identify-russian-snake-malware-infrastructure/

[2] https://media.defense.gov/2023/May/09/2003218554/-1/-1/1/JOINT_CSA_HUNTING_RU_INTEL_SNAKE_MALWARE_20230509.PDF

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZFrCg5lU-vWG-BXUSVrskQAAAM0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://regmedia.co.uk/2023/05/09/operation_medusa_affidavit.pdf

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZFrCg5lU-vWG-BXUSVrskQAAAM0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZFrCg5lU-vWG-BXUSVrskQAAAM0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://regmedia.co.uk/2023/05/09/operation_medusa_warrant.pdf

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZFrCg5lU-vWG-BXUSVrskQAAAM0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://www.justice.gov/usao-edny/pr/justice-department-announces-court-authorized-disruption-snake-malware-network

[10] https://www.theregister.com/2023/05/02/monopoly_market_arrests/

[11] https://www.theregister.com/2023/04/05/genesis_market_takedown/

[12] https://www.theregister.com/2023/04/14/un_cybercrime_treaty/

[13] https://www.theregister.com/2023/01/26/fbi_hive_ransomware/

[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZFrCg5lU-vWG-BXUSVrskQAAAM0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[15] https://www.theregister.com/2023/05/09/intel_oem_private_keys_leaked/

[16] https://www.theregister.com/2023/05/02/monopoly_market_arrests/

[17] https://whitepapers.theregister.com/



Meanwhile in the black sea...

Clausewitz4.0

lucky12345 sips his vodka and prepares his next project, probably badly implicating the FBI itself.

As a buch of people are now too afraid to collect the US$ 10.000.000 million dollars on his head, because it is too risky - I heard people have tried and are now dead.

Boys, you have ALL been selected to LEAVE th' PLANET in 15 minutes!!