Overview
Snake is a cyber espionage implant developed and operated by a unit within Center 16 of Russia's Federal Security Service (FSB). CISA, the FBI, NSA, and Five Eyes partner agencies describe Snake as the most sophisticated cyber espionage tool in the FSB's arsenal. Development began in late 2003 under the internal name "Uroburos," and the implant has been continuously re-engineered for almost two decades rather than retired after public disclosure. The broader toolset built around Snake is publicly tracked as Turla, alongside related implants including Carbon (aka Cobra) and Chinch (publicly known as ComRAT).
Snake operated as a covert peer-to-peer network of infected hosts spanning more than 50 countries, including the United States and Russia itself. The FSB used Snake to exfiltrate sensitive international relations documents and diplomatic communications from a NATO-member victim, and to target education, media, financial services, government facilities, critical manufacturing, and communications organizations in the United States. Daily Snake operations were conducted from an FSB facility in Ryazan, Russia, with activity concentrated during FSB business hours in Moscow Standard Time.
On May 9, 2023, the FBI disrupted the Snake peer-to-peer network in a coordinated action known as Operation MEDUSA. The FBI developed a tool named PERSEUS that exploited weaknesses in Snake's own authentication protocol to issue self-disabling commands to infected hosts without disrupting legitimate use of the compromised machines. CISA and partner agencies published a 48-page joint advisory (AA23-129A) alongside the takedown, detailing Snake's host architecture, network protocols, and detection methodology.
Disabling the implant did not remove FSB access gained through other means. The advisory warned that Turla operators routinely deploy a keylogger alongside Snake and separately obtain administrator credentials during an intrusion, so stolen credentials can outlive the malware itself. In a separate 2023 operation, the group was observed hijacking expired command-and-control domains belonging to the decade-old ANDROMEDA commodity malware to selectively deliver the Kopiluwak reconnaissance utility and QuietCanary backdoor against Ukrainian targets, reusing someone else's infected USB infrastructure rather than gaining initial access itself.