Showing posts with label Russian FSB. Show all posts
Showing posts with label Russian FSB. Show all posts

Thursday, May 11, 2023

Justice Department Announces Court-Authorized Disruption Of The Snake Malware Network Controlled By Russia's Federal Security Service


The Justice Department on May 9th announced the completion of a court-authorized operation, codenamed MEDUSA, to disrupt a global peer-to-peer network of computers compromised by sophisticated malware, called “Snake”, that the United States Government attributes to a unit within Center 16 of the Federal Security Service of the Russian Federation (FSB). 

For nearly 20 years, this unit, referred to in court documents as “Turla,” has used versions of the Snake malware to steal sensitive documents from hundreds of computer systems in at least 50 countries, which have belonged to North Atlantic Treaty Organization (NATO) member governments, journalists, and other targets of interest to the Russian Federation.  After stealing these documents, Turla exfiltrated them through a covert network of unwitting Snake-compromised computers in the United States and around the world. 

Operation MEDUSA disabled Turla’s Snake malware on compromised computers through the use of an FBI-created tool named PERSEUS, which issued commands that caused the Snake malware to overwrite its own vital components.  Within the United States, the operation was executed by the FBI pursuant to a search warrant issued by United States Magistrate Judge Cheryl L. Pollak of the Eastern District of New York, which authorized remote access to the compromised computers.  This morning, the Court unsealed redacted versions of the affidavit submitted in support of the application for the search warrant, and of the search warrant issued by the Court.  For victims outside the United States, the FBI is engaging with local authorities to provide both notice of Snake infections within those authorities’ countries and remediation guidance.

Merrick B. Garland, United States Attorney General; Breon Peace, United States Attorney for the Eastern District of New York; Lisa O. Monaco, Deputy Attorney General of the Justice Department; and Michael J. Driscoll, Assistant Director-in-Charge, FBI, New York Field Office, announced the operation.

“The Justice Department, together with our international partners, has dismantled a global network of malware-infected computers that the Russian government has used for nearly two decades to conduct cyber-espionage, including against our NATO allies,” stated Attorney General Garland.  “We will continue to strengthen our collective defenses against the Russian regime’s destabilizing efforts to undermine the security of the United States and our allies.”

“Russia used sophisticated malware to steal sensitive information from our allies, laundering it through a network of infected computers in the United States in a cynical attempt to conceal their crimes.  Meeting the challenge of cyberespionage requires creativity and a willingness to use all lawful means to protect our nation and our allies,” stated United States Attorney Peace.  “The court-authorized remote search and remediation announced today demonstrates my Office and our partners’ commitment to using all of the tools at our disposal to protect the American people.”

 “Through a high-tech operation that turned Russian malware against itself, U.S. law enforcement has neutralized one of Russia’s most sophisticated cyber-espionage tools, used for two decades to advance Russia’s authoritarian objectives,” stated Deputy Attorney General Monaco.  “By combining this action with the release of the information victims need to protect themselves, the Justice Department continues to put victims at the center of our cybercrime work and take the fight to malicious cyber actors.”

“The operation we announced today successfully disrupted the foremost cyber espionage tool of the Russian government.  For two decades, the malware allowed Russian Intelligence to compromise computer systems and steal sensitive information - harming not only the United States Government and our allies but also private sector organizations.  This action should serve as a reminder to Russia and any other hostile nation willing to steal information, the FBI and our partners are united in our efforts to protect our countries,” stated FBI Assistant Director-in-Charge Driscoll.

“For 20 years, the FSB has relied on the Snake malware to conduct cyberespionage against the United States and our allies – that ends today,” said Assistant Attorney General Matthew G. Olsen of the Justice Department’s National Security Division. “The Justice Department will use every weapon in our arsenal to combat Russia’s malicious cyber activity, including neutralizing malware through high-tech operations, making innovative use of legal authorities, and working with international allies and private sector partners to amplify our collective impact.”

As detailed in court documents, the U.S. government has been investigating Snake and Snake-related malware tools for nearly 20 years. The U.S. government has monitored FSB officers assigned to Turla conducting daily operations using Snake from a known FSB facility in Ryazan, Russia. 

Although Snake has been the subject to several cybersecurity industry reports throughout its existence, Turla has applied numerous upgrades and revisions, and selectively deployed it, all to ensure that Snake remains the FSB’s most sophisticated long-term cyberespionage malware implant.  Unless disrupted, the Snake implant persists on a compromised computer’s system indefinitely, typically undetected by the machine’s owner or authorized users.  The FBI has observed Snake persist on particular computers despite a victim’s efforts to remediate the compromise.

Snake provides its Turla operators the ability to remotely deploy selected malware tools to extend Snake’s functionality to identify and steal sensitive information and documents stored on a particular machine.  Most importantly, the worldwide collection of Snake-compromised computers acts as a covert peer-to-peer network, which utilizes customized communication protocols designed to hamper detection, monitoring, and collection efforts by Western and other signals intelligence services. 

Turla uses the Snake network to route data exfiltrated from target systems through numerous relay nodes scattered around the world back to Turla operators in Russia.  For example, the FBI, its partners in the U.S. Intelligence Community, together with allied foreign governments, have monitored the FSB’s use of the Snake network to exfiltrate data from sensitive computer systems, including those operated by NATO member governments, by routing the transmission of these stolen data through unwitting Snake-compromised computers in the United States.

As described in court documents, through analysis of the Snake malware and the Snake network, the FBI developed the capability to decrypt and decode Snake communications.  With information gleaned from monitoring the Snake network and analyzing Snake malware, the FBI developed a tool, named PERSEUS, that establishes communication sessions with the Snake malware implant on a particular computer, and issues commands that causes the Snake implant to disable itself without affecting the host computer or legitimate applications on the computer.

Today, to empower network defenders worldwide, the FBI, the National Security Agency, the Cybersecurity and Infrastructure Security Agency, the U.S. Cyber Command Cyber National Mission Force, and six other intelligence and cybersecurity agencies from each of the Five Eyes member nations, issued a joint cybersecurity advisory (the “Joint Advisory”) with detailed technical information about the Snake malware that will allow cybersecurity professionals to detect and remediate Snake malware infections on their networks.  The Joint Advisory is available here.  The FBI and U.S. Department of State are also providing additional information to local authorities in countries where computers that have been targeted by the Snake malware have been located.

Although Operation MEDUSA disabled the Snake malware on compromised computers, victims should take additional steps to protect themselves from further harm.  The operation to disable Snake did not patch any vulnerabilities or search for or remove any additional malware or hacking tools that hacking groups may have placed on victim networks.  The Department of Justice strongly encourages network defenders to review the Joint Advisory for further guidance on detection and patching.  Moreover, as noted in court documents, Turla frequently deploys a “keylogger” with Snake that Turla can use to steal account authentication credentials, such as usernames and passwords, from legitimate users.  Victims should be aware that Turla could use these stolen credentials to fraudulently re-access compromised computers and other accounts.

The FBI has is providing notice of the court-authorized operation to all owners or operators of the computers remotely accessed pursuant to the search warrant.

The criminal investigation into the FSB’s use of the Snake malware is being handled by the Office’s National Security and Cybercrime Section.  Assistant United States Attorney Ian C. Richardson is in charge of the investigation, with assistance from the National Security Division’s Counterintelligence and Export Control Section.

The efforts to disrupt the Snake malware network were led by the FBI’s New York Field Office, FBI’s Cyber Division, the U.S. Attorney’s Office for the Eastern District of New York, and the National Security Division’s Counterintelligence and Export Control Section.  Assistance was also provided by the Criminal Division’s Computer Crime and Intellectual Property Section.

Those efforts would not have been successful without the partnership of numerous private-sector entities, including those victims who allowed the FBI to monitor Snake communications on their systems.

The Search Warrant:

In the Matter of the Search of Information Associated with Computers Constituting the Snake Malware Network

Eastern District of New York Docket No. 23-MJ-0428 (CLP)

 

Wednesday, May 30, 2018

International Hacker-For-Hire Who Conspired With And Aided Russian FSB Officers Sentenced To 60 Months in Prison


The U.S. Justice Department released the below information:

Karim Baratov, aka Kay, aka Karim Taloverov, aka Karim Akehmet Tokbergenov, 23, was sentenced to five years in prison and ordered to pay a fine, which encompasses all of his remaining assets.

Assistant Attorney General for National Security John C. Demers, Acting U.S. Attorney Alex G. Tse for the Northern District of California, and Special Agent in Charge John F. Bennett of the FBI’s San Francisco Field Office made the announcement.  The sentence was handed down today by U.S. District Judge the Honorable Vince Chhabria.

“Criminal hackers and the countries that sponsor them make a grave mistake when they target American companies and citizens.  We will identify them wherever they are and bring them to justice,” said Assistant Attorney General Demers.  “I would like to thank Canadian law enforcement authorities for their tremendous assistance in bringing Baratov to justice.  We will continue to work with our foreign partners to find and prosecute those who would violate our laws.”

“The sentence imposed reflects the seriousness of hacking for hire,” said Acting U.S. Attorney Tse.  “Hackers such as Baratov ply their trade without regard for the criminal objectives of the people who hire and pay them.  These hackers are not minor players; they are a critical tool used by criminals to obtain and exploit personal information illegally.  In sentencing Baratov to five years in prison, the Court sent a clear message to hackers that participating in cyber attacks sponsored by nation states will result in significant consequences.”

“It's difficult to overstate the unprecedented nature of this conspiracy, in which members of a foreign intelligence service directed and empowered criminal hackers to conduct a massive cyber-attack against 500 million victim user accounts,” said Special Agent in Charge Bennett.  “Today's sentencing demonstrates the FBI's unwavering commitment to disrupt and prosecute malicious cyber actors despite their attempts to conceal their identities and hide from justice.”

Baratov, a Canadian national and resident, and three other defendants, including two officers of the Russian Federal Security Service (FSB), Russia’s domestic law enforcement and intelligence service, were charged with a number of offenses relating to the hacking of webmail accounts at Yahoo and other service providers.  In particular, the defendants were charged in a computer hacking conspiracy in which the two Russian FSB officers hired criminal hackers to collect information through computer intrusions in the United States and abroad, which resulted in the unauthorized access of Yahoo’s network and the spear phishing of webmail accounts at other service providers between January 2014 and December 2016.

Baratov’s role in the charged conspiracy was to hack webmail accounts of individuals of interest to his coconspirator who was working for the FSB and send those accounts’ passwords to Dokuchaev in exchange for money.

The Indictment is available here, and its allegations are summarized in greater detail in the press release that attended the unsealing of the Indictment on March 15, 2017.

Baratov has been detained since his arrest in Canada in March 2017.  Baratov waived extradition to the United States and was transferred to the Northern District of California in August 2017.  In November 2017, Baratov pleaded guilty to Count One and Counts Forty through Forty-Seven of the Indictment.  Count One charged Baratov, Dokuchaev, Sushchin and Belan with conspiring to violate the Computer Fraud and Abuse Act by stealing information from protected computers and causing damage to protected computers.  Counts Forty through Forty-Seven charged Baratov and Dokuchaev with aggravated identity theft.  As part of his plea agreement, Baratov not only admitted to agreeing and attempting to hack at least 80 webmail accounts on behalf of one of his FSB co-conspirators, but also to hacking more than 11,000 webmail accounts in total from in or around 2010 until his March 2017 arrest by Canadian authorities.  In addition to any prison sentence, Baratov agreed to pay restitution to his victims, and to pay a fine up to $2,250,000, at $250,000 per count, with any assets he has remaining after satisfying a restitution award.

The FBI, led by the San Francisco Field Office, conducted the investigation that resulted in the charges in the Indictment.  The case is being prosecuted by the U.S. Attorney’s Office for the Northern District of California and the U.S. Department of Justice National Security Division’s Counterintelligence and Export Control Section, with support from the Justice Department’s Office of International Affairs. 

Thursday, January 21, 2016

Ex-KGB Spy Was Killed Because He Claimed Putin Was A Pedophile


Yaron Steinbuch at the New York Post offers a piece on the murder of former KGB officer Alexander Litvinko in the United Kingdom.

The Russian government likely ordered Alexander Litvinenko’s assassination in part because he accused Russian President Vladimir Putin of being a pedophile, a British inquiry concluded Thursday.
In the 300-page report, retired High Court judge Sir Robert Owen said Putin “probably” ordered the hit against Alexander Litvinenko, and used his position as head of Russian intelligence to destroy video evidence of himself having sex with underage boys — which was “the climax” of a bitter feud between the two men.
Owen said the personal attacks were among the “powerful motives” for the assassination.
“I am satisfied that, in general terms, members of the Putin administration, including the president himself and the FSB [Russia’s Federal Security Service], had motives for taking action against Litvinenko, including killing him,” Owen wrote.
.. “The FSB operation to kill Mr. Litvinenko was probably approved by Mr. Patrushev, then head of the FSB, and also by President Putin,” Owen said.
You can read the rest of the piece via the below link:

After Putin Ordered MURDER On British Streets David Cameron Admits He Has To Deal With The Russians - But Only With A 'Very Cold Heart' In A Diplomatic Stand-Off As Moscow Refuses To Hand Over The Litvinenko Assassins


The British newspaper the Daily Mail offers a piece on a report that accuses Russian leader VladimirPutin of ordering the murder of Alexander Litvinko in the UK.

A public inquiry into the assassination of Alexander Litvinenko prompted a furious diplomatic row between Britain and Russia today after the independent probe said President Putin had 'probably' personally authorised the 2006 killing.

Mr Litvinenko - who had accused the Russian president on his death bed - was killed by two FSB spies who slipped radioactive polonium 210 into his tea pot at a Mayfair hotel in central London, Sir Robert Owen said today in a major report.

Prime Minister David Cameron today said the report outlined what happened was 'absolutely appalling' but he admitted the Syria crisis meant Britain had to have a relationship with Russia albeit one with 'clear eyes and a cold heart'.

You can read the rest of the piece, view photos and watch a video clip via the below link:

http://www.dailymail.co.uk/news/article-3409405/Inquiry-says-Litvinenko-killed-Putin-s-spies.html

Sunday, January 19, 2014

Command Authority: Tom Clancy's Last Thriller


Veteran journalist and author Joseph C. Goulden offers a good review of Tom Clancy's Command Authority in the Washington Times.

A feeling of sad finality gripped me as I read the last of the 739 pages of Tom Clancy's 18th and final thriller. Once again, the acrid scent of cordite wafted through my imagination during the climactic gunbattle as Clancy’s characters from the world of intelligence achieved yet another victory over the forces of evil.

Clancy, who died on Oct. 1 at 66, had boosters as disparate as President Ronald Reagan, who pronounced “The Hunt for Red October,” his first of 18 books, “the perfect yarn” and “non-put-downable.” National Public Radio's Alan Cheuse called him “Faulkner in a flak suit.”

Let’s be blunt about it. Clancy
was an acquired taste — beloved by patriots who support a strong military and an effective intelligence community; mocked by leftist woo-woos who argue that a turned-cheek is the best defense against an adversary.

Clancy was an unabashed hard-liner. In his first novels, his heroes fought the USSR and its KGB. When the Iron Curtain tumbled, burying world communism under a heap of rubble, he made a seamless segue into a war against terrorism. I was one of the millions of fans who put him on the best-seller list for 17 straight books.

In “Command Authority,” Clancy 
has at it again with his original foes, correctly equating the current regime in Moscow as merely a relabeled version of what Reagan once termed “the evil empire.” The Russian president, one Valeri Volodin (somewhat rhymes with “Putin,” eh?) is threatening the military annexation of  Estonia, Ukraine and other former states of the USSR. 

Volodin's plan includes enhanced powers for the FSB, successor to the KGB as a vehicle to subvert his targets from within. He accuses the United States and other Western powers of instigating anti-Russian provocations in Estonia.

You can read the rest of the review via the below link:

http://www.washingtontimes.com/news/2014/jan/17/book-review-tom-clancys-final-thriller/

Note: In 1984 my wife and I visited Jamaica, our favorite vacation island. I brought along several thrillers to read, including Tom Clancy's The Hunt for Red October.

I had not heard of Clancy at this point, but being a Defense Department civilian employee, as well as a Navy veteran who spent two years on an aircraft carrier during the Vietnam War and another two years on a Navy tugboat at the nuclear submarine base at Holy Loch, Scotland, I was drawn to the novel by the subject matter.

Reading the book on the beach and by the pool, I was surprised at how accurate the details were (he even got the nickname right of a phone dropped into the sea by surface craft to communicate with submarines), and I was even more surprised at his detailing what I believed at the time was classified information. (I later discovered that I was wrong - the information had been declassified).

I became a Clancy fan and I've enjoyed reading all of his subsequent thrillers and his nonfiction books.

Tom Clancy died far too young at 66 and he shall be missed.

Wednesday, March 23, 2011

Meet The New Russian Secret Police, Same As The Old Russian Secret Police

Joseph G. Goulden, author of The Death Merchant, reviewed a new book on the Russian security service called The New Nobility: The Restoration of Russia's Security State and the Enduring Legacy of the KGB (Public Affairs). The book was written by Andrei Soldatov and Irina Borogan.

Goulden wrote the below:

No one familiar with the security system of the old USSR expected the KGB to dry up and blow away when communism collapsed in 1991. Further, many of us doubted whatever government replaced the Soviet state would make any changes of substance in its intelligence agencies.

Skepticism is proving well-founded. Indeed, the newly constituted security services are more shadowy and powerful than was the KGB at its prime. The Federal Security Service (Federalnaya Sluzhba Bezopasnosti, or FSB) has flourished under former KGB officer Vladimir Putin - first as president, now prime minister - and the government is top-heavy with his onetime intelligence colleagues.

The book sounds interesting.

You can read the rest of the review in the The Washington Times via the below link:

http://www.washingtontimes.com/news/2011/mar/22/heirs-to-the-kgb-and-czars-police/print/#

Sunday, November 21, 2010

Russian Spy Agencies Under Fire for Their Rank Amateur Peformance

Vladimir Putin, the ex-KGB officer and current Prime Minister of Russia, is suffering criticism of his spy agencies, according to the Scottish newspaper The Herald.

The FBI's round up of the Russian spy ring in the United States and other intelligence failures have made the once powerful Soviet spy agencies look like rank amateurs.

You can read the newspaper story via the link below:

http://www.heraldscotland.com/news/world-news/a-cold-fallout-russia-s-spies-go-to-war-1.1069804

You can also read an earlier post on the Russian spy ring via the below link:

http://pauldavisoncrime.blogspot.com/2010/11/first-look-at-russian-defector-who-blew.html