-
Edgar Davids art thief misses sentencing after being 'knocked out by luggage'
-
Defending champ Sabalenka, Pegula lead way into US Open fourth round
-
Pegula rallies to reach US Open fourth round
-
UK hard-right party rallies behind leader after new donation scandal
-
Defending champ Sabalenka leads way into US Open fourth round
-
Nigeria's Dangote refinery looks to raise $1.6 bn in IPO
-
Bayeux Tapestry 'virtually unchanged', UK museum says, after France spots broken threads
-
Portugal extends talks to privatise national carrier TAP
-
More than 120 killed in Yemen's worst clashes in years: sources
-
Brazil great Formiga says 2027 World Cup will 'change players' lives'
-
Germany hunts climate activist suspected of power grid sabotage
-
Job growth, but surging diesel prices - Trump's midterms mixed bag
-
5 EU countries aim to send rejected migrants to 'return hub' by 2027
-
Top seed Sabalenka powers into US Open fourth round
-
Argentina to return Nazi-looted painting to Jewish collector's heir
-
Russia rights group boss fears post-election crackdown
-
Australian Simmons makes NBA comeback with Kings: reports
-
WHO says key warehouse destroyed by attack in Ukraine
-
Two broken threads on Bayeux Tapestry, no major damage: French minister
-
Hesson says Pakistan players used to 'chaos' after shake-up
-
Meloni marks record in power with eye on 2027 elections
-
Bosnian Serb war criminal to be buried Monday, amid EU backlash
-
Israel emptying West Bank refugee camps could be crime against humanity: UN
-
Julio Iglesias faces new abuse complaint
-
Portugal extends talks to privatise airline
-
Walter made improper deal with Magic after buying Dodgers: report
-
CoinRabbit Wins “Best Crypto Lending Platform 2026” Award from International Business Magazine
-
Russia targets security chief's office in daylight Kyiv strike: Zelensky
-
Judge declares mistrial in US infanticide case but puts ruling on hold
-
Moyes voices disappointment with Everton's threadbare squad
-
US midterms begin with chaos over mail-voting crackdown
-
Argentina ordered to return Nazi-looted painting to Jewish collector's heir
-
Russell tops second practice to beat Ferrari and Antonelli in Italy
-
Director Maggie Gyllenhaal ditched AI for Marilyn Monroe film
-
'I love the players we have', insists Arsenal boss Arteta
-
'Winner' Fernandez fundamental to Maresca's Man City rebuild
-
Jury resumes deliberations in case of US mother who killed her three children
-
Song Yadong looks to become China's first male UFC champion after home victory
-
Farage's Reform UK meets under cloud of new donation scandal
-
Russia hits SBU headquarters, Ukraine says security chief's office was target
-
Man Utd in 'good place' despite imperfect squad, says Carrick
-
US shows strong job growth in August in boon to Trump
-
Le Pen party sparks furore with 'turn off tap' to Ukraine call
-
Alonso urges Chelsea to 'move forward' after Fernandez's exit
-
Emery says Madjo's time will come after Villa Euro exclusion
-
US safety regulator probes Tesla's Cybercab
-
Workers reeling after VW cuts open door to factory closures
-
Voting begins in crucial US midterm elections
-
Liquid Mercury Announces Initial Closing of ACQUA1 Offering
-
US shows strong job growth in August in boon to Trump ahead of midterms
US says disabled Russian spyware used for two decades
The US Justice Department said Tuesday that it had disabled a "sophisticated" malware network used by Russia's FSB intelligence agency for two decades to spy in 50 countries including a NATO ally.
The FSB had successfully inserted the "Snake" or "Uroburos" malware on computer systems around the world, focused on government networks, research facilities, journalists and other targets, according to US officials.
Computers in the system also served as relay nodes to disguise traffic to and from Snake malware inserted on target computer systems, they said.
In a years-long operation, the FBI was able to defeat Snake by inserting its own bit of computer code into it, which issued commands causing the malware to overwrite itself, the Justice Department said.
"Through a high-tech operation that turned Russian malware against itself, US law enforcement has neutralized one of Russia's most sophisticated cyber-espionage tools, used for two decades to advance Russia's authoritarian objectives," said Deputy Attorney General Lisa Monaco.
The malware has been known by computer security experts for at least a decade, and CISA, the US cyber defense agency, said the FSB began developing it in 2003.
CISA called Snake "the most sophisticated cyber espionage tool in the FSB's arsenal," noting that it was particularly stealthy, extremely hard to detect in computer systems and network traffic.
In addition, it was designed for easy updating and modification, and yet had "surprisingly few bugs given its complexity," CISA said.
Those aspects allowed the FSB to work undetected for years through sprawling host networks to get into computers with sensitive documents.
At least in one case Snake was placed on the systems of an unnamed NATO country, allowing Russian intelligence to access and exfiltrate sensitive international relations documents and diplomatic communications, CISA said.
"The effectiveness of this type of cyber espionage implant depends entirely on its long-term stealth," the agency said.
- FBI hacks back -
Previous official and news reports have indicated that Snake and related software has been found on government systems in Germany, Belgium, Ukraine and Switzerland.
CISA said US investigators had traced the malware's development to an FSB unit known as Center 16 operating out of Ryazan, Russia, and its operation from an office the unit has in Moscow.
CISA said it and cyber experts in allies have been investigating the unit and its hacking tools -- more broadly known as the Turla toolset -- for almost 20 years.
The FSB has adapted it for use in Windows, MacOS, and Linux operating systems, and even when it was exposed as a threat by computer security firms, the Russians were able to modify it to keep it hidden and functional.
But Snake's sophistication led to errors in using it by less skillful FSB operators, which allowed Western investigators to permeate its inner workings and track the malware, CISA said.
The Justice Department said the FBI developed a tool dubbed Perseus, that rendered the Russian malware ineffective.
Perseus "establishes communication sessions with the Snake malware implant on a particular computer, and issues commands that causes the Snake implant to disable itself without affecting the host computer or legitimate applications on the computer," the department said.
Despite the success the Perseus implant, Snake malware is still a threat, according to a joint advisory issued Tuesday from cyber authorities in the United States, Canada, Britain, Australia and New Zealand.
J.Bergmann--BTB