US-led ‘Five Eyes’ alliance dismantled Russia’s ‘premier espionage cyber-tool’
May 11, 2023 3 Comments
AN ESPIONAGE TOOL DESCRIBED by Western officials as the most advanced in the Russian cyber-arsenal has been neutralized after a 20-year operation by intelligence agencies in the United States, Australia, Canada, the United Kingdom and New Zealand. The operation targeted Turla, a hacker group that cyber-security experts have long associated with the Russian government.
Turla is believed to be made up of officers from Center 16, a signals intelligence unit of Russia’s Federal Security Service (FSB), one of the Soviet-era KGB’s successor agencies. Since its appearance in 2003, Turla has used a highly sophisticated malware dubbed ‘Snake’ to infect thousands of computer systems in over 50 countries around the world. Turla’s victims include highly sensitive government computer networks in the United States, including those of the Department of Defense, the National Aeronautics and Space Administration, and the United States Central Command.
The Snake malware has also been found in computers of privately owned firms, especially those belonging to various critical infrastructure sectors, such as financial services, government facilities, electronics manufacturing, telecommunications and healthcare. For over two decades, the Snake malware used thousands of compromised computers throughout the West as nodes in complex peer-to-peer networks. By siphoning information through these networks, the Turla hackers were able to mask the location from where they launched their attacks.
On Tuesday, however, the United States Department of Justice announced that the Federal Bureau of Investigation (FBI), along with its counterparts in the United States-led ‘Five Eyes’ intelligence-sharing alliance, had managed to dismantle Snake. This effort, codenamed Operation MEDUSA, was reportedly launched nearly 20 years ago with the goal of neutralizing the Snake malware. In the process, Five Eyes cyber-defense experts managed to locate Turla’s facilities in Moscow, as well as in Ryazan, an industrial center located about 120 miles southeast of the Russian capital.
The complex cyber-defense operation culminated with the development of an anti-malware tool that the FBI dubbed PERSEUS. According to the Department of Justice’s announcement, PERSEUS was designed to impersonate the Turla operators of Snake. In doing so, it was able to take over Snake’s command-and-control functions. Essentially, PERSEUS hacked into Snake and instructed the malware to self-delete from the computers it had compromised. As of this week, therefore, the worldwide peer-to-peer network that Snake had painstakingly created over two decades, has ceased to exist, as has Snake itself.
► Author: Joseph Fitsanakis | Date: 11 May 2023 | Permalink
A UKRAINIAN PARAMILITARY GROUP has claimed to be behind a targeted attack against an influential figure in Russian literature and social media on Saturday, which killed his fellow passenger and prompted strong denouncements by the Kremlin. The attack appeared to target Yevgeny Nikolayevich Prilepin, 47, known in Russia as Zakhar Prilepin. One of the best-known novelists in Russia, Prilepin spent much of his late teens and early twenties serving in the Russian National Guard. He saw action during two tours in Chechnya.
OFFICIALS IN UKRAINE HAVE
Russia’s border with Belarus, two trains were
AUTHORITIES IN POLAND HAVE seized an abandoned school building in the Polish capital Warsaw, allegedly because it was being used as a base for espionage activities by the Russian government. Following the seizure of the building complex, Russian officials issued stern but vague warnings, saying that action will be taken in response to what they termed as an “act of provocation” by the Polish government.
A NEW REPORT PUBLISHED by a London-based security think-tank concludes that Russia has employed unconventional operations effectively to subdue the population in occupied areas of Ukraine. These successes contrast sharply with the inferior performance of Russia’s conventional military forces, as revealed last week in a series of leaked documents belonging to the United States Department of Defense.
A POWERFUL EXPLOSION, LIKELY caused by a bomb hidden inside a decorative figurine, has killed one of the most prominent pro-Kremlin bloggers as he was giving a public talk in downtown St. Petersburgh, Russia. The bomb killed Maxim Fomin, 40, who was known in online blogger circles under the pseudonym Vladlen Tatarsky. Born in eastern Ukraine, Fomin supported the pro-Russian secessionist movement in the Donbas. By 2021, when he obtained Russian citizenship, he had already made a name for himself as a pro-Kremlin military blogger on the Telegram social media platform.
A RUSSIAN INTELLIGENCE OPERATIVE, who lived in Maryland using forged Brazilian identity documents, has been charged with espionage and other crimes by the United States Department of Justice. Victor Muller Ferreira, a Brazilian national, was stopped from entering the Netherlands in June of last year, where he had intended to join the International Criminal Court (ICC) as an intern.
GREEK INTELLIGENCE OFFICIALS ANNOUNCED late last week that they had uncovered the identity of a female Russian spy who lived in central Athens using a set of forged identity documents. According to the Greek National Intelligence Service (NIS/EYP), the case is under investigation by several Western intelligence agencies. Additionally, there seems to be a connection with Brazil where the Russian spy’s husband lived until recently, using forged identity papers.
THE GOVERNMENT OF AUSTRALIA has ordered the deportation of a Kazakh-born Irish citizen, who is believed to be a spy for the Russian Federation, according to reports from Australia and Ireland. The woman in question has been identified as Marina Sologub, 39, an ethnic Russian who was born in Kazakhstan, but grew up in the Republic of Ireland.
THE RUSSIAN INTELLIGENCE SERVICES are “covertly mapping” the energy infrastructure of the North Sea, in preparation for acts of disruption and sabotage, according to a new report form the Dutch government. The 32-page
RUSSIA’S ABILITY TO CONDUCT human intelligence operations in Europe has suffered greater damage in recent years than at any time since 1991, according to some experts. These setbacks have partly been caused by what The Washington Post refers to in a
A LEADING RUSSIAN NATIONALIST, who styled himself as the originator of ‘Z’, the symbol of the Russian campaign in Ukraine, has
GERMANY’S EXTERNAL INTELLIGENCE AGENCY, the Federal Intelligence Service (BND), constitutes a liability for Europe’s security and is in desperate need of a drastic and immediate overhaul. That is the conclusion of a blunt 






U.S., Russian spy agencies publish rival ads encouraging would-be informants
May 18, 2023 by Joseph Fitsanakis 2 Comments
The FBI ad initially appeared on Twitter, directing users to the website of the Bureau’s Washington Field Office. There, a text in Cyrillic urges Russian nationals to “change [their] future” by contacting the FBI. The CIA followed suit on Monday of this week by posting a video on its new channel on Telegraph, a popular social media platform among young Russians. The CIA video portrays frustrated Russian government employees morally torn by the Kremlin’s policies. It concludes with them contacting the CIA through a secure online connection. A narrator’s voice states, “my family will live with dignity thanks to my actions”. Viewers are then assured that their safety is the CIA’s highest priority, should the choose to do the same.
Shortly after the CIA video appeared online, the Russian Ministry of Foreign Affairs’ Director of Information, Maria Zakharova, said that the Russian government would respond “appropriately” to what she called a “CIA provocation”. On Wednesday, a number of Western media outlets reported that the SVR had unveiled a short recruitment video seemingly targeting Americans. The video, shared on Telegram, includes archival news footage of United States military and police personnel, flag-burning demonstrators, and protests against abortions. It concludes with footage of President Joe Biden overlaid with a sniper crosshairs. A narrator states in English: “If you want to help normalcy, help the Foreign Intelligence Service of the Russian Federation”.
Amid the ongoing war in Ukraine, both the United States and Russia are engaging in extensive cyber-enabled operations aimed at each other’s targets. However, these recruitment videos underscore the continued need for highly placed human sources and their central role in multi-platform intelligence collection efforts.
► Author: Joseph Fitsanakis | Date: 18 May 2023 | Permalink
Filed under Expert news and commentary on intelligence, espionage, spies and spying Tagged with CIA, espionge, FBI, HUMINT, News, Russia, social networking, SVR (Russia), United States