Turla (Snake)

Cyber espionage implant (state-sponsored) · FSB Center 16 · First developed 2003 · Snake infrastructure dismantled May 9, 2023 (Operation MEDUSA) ·

Overview

Snake is a cyber espionage implant developed and operated by a unit within Center 16 of Russia's Federal Security Service (FSB). CISA, the FBI, NSA, and Five Eyes partner agencies describe Snake as the most sophisticated cyber espionage tool in the FSB's arsenal. Development began in late 2003 under the internal name "Uroburos," and the implant has been continuously re-engineered for almost two decades rather than retired after public disclosure. The broader toolset built around Snake is publicly tracked as Turla, alongside related implants including Carbon (aka Cobra) and Chinch (publicly known as ComRAT).

Snake operated as a covert peer-to-peer network of infected hosts spanning more than 50 countries, including the United States and Russia itself. The FSB used Snake to exfiltrate sensitive international relations documents and diplomatic communications from a NATO-member victim, and to target education, media, financial services, government facilities, critical manufacturing, and communications organizations in the United States. Daily Snake operations were conducted from an FSB facility in Ryazan, Russia, with activity concentrated during FSB business hours in Moscow Standard Time.

On May 9, 2023, the FBI disrupted the Snake peer-to-peer network in a coordinated action known as Operation MEDUSA. The FBI developed a tool named PERSEUS that exploited weaknesses in Snake's own authentication protocol to issue self-disabling commands to infected hosts without disrupting legitimate use of the compromised machines. CISA and partner agencies published a 48-page joint advisory (AA23-129A) alongside the takedown, detailing Snake's host architecture, network protocols, and detection methodology.

Disabling the implant did not remove FSB access gained through other means. The advisory warned that Turla operators routinely deploy a keylogger alongside Snake and separately obtain administrator credentials during an intrusion, so stolen credentials can outlive the malware itself. In a separate 2023 operation, the group was observed hijacking expired command-and-control domains belonging to the decade-old ANDROMEDA commodity malware to selectively deliver the Kopiluwak reconnaissance utility and QuietCanary backdoor against Ukrainian targets, reusing someone else's infected USB infrastructure rather than gaining initial access itself.

Operational attack chain · Intrusion-to-passive-exfiltration
  1. Ingress vector

    Exploited internet-facing host, spearphishing, or hijacked legacy C2.

  2. Installer chain runs

    jpsetup.exe (disguised as JPEG viewer) decrypts and runs Stage 2.

  3. Service persistence set

    WerFaultSvc + kernel driver loaded from comadmin.dat on every boot.

  4. Kernel-mode concealment

    Driver hides files, intercepts TCP sessions; covert CAST-128 encrypted store.

  5. Credential and network access

    Keylogger, network sniffers, open-source tools; domain controller access obtained.

  6. P2P relay to operator

    Forward commands hop across infected nodes; passive beaconing to queued C2 channels.

  7. Intelligence collection

    Documents, comms, and credentials exfiltrated passively to FSB operators.

    FSB Center 16State espionage

Snake's kill chain is designed for years-long persistence rather than rapid impact. Most of the engineering effort documented by CISA and the FBI sits in stages 3 and 5: staying undetected and moving stolen data through a relay network without opening new listening ports.

Stop threats before they spread

Detect malicious behavior, contain affected endpoints, and remediate attacks with Malware Protection Plus.

Free for 30 days. Unlimited endpoints. No credit card required.

Tactics, techniques, and procedures

Snake maps most heavily to Defense Evasion and Command and Control, reflecting an implant built primarily for long-term concealment rather than fast objective completion. The coverage below combines MITRE ATT&CK technique references from the CISA/FBI advisory with the MITRE ATT&CK Turla (G0010) group page.

Technique detailKey techniques · Turla / Snake
TacticTechniquesWhat Snake / Turla does
Resource DevelopmentSnake is FSB-developed and continuously re-engineered in-house. Turla also compromises third-party servers to use as P2P relay infrastructure rather than standing up new, easily attributed hosts.
Initial AccessSnake is placed on external-facing infrastructure nodes as a beachhead. In a related 2023 operation, Turla hijacked expired ANDROMEDA C2 domains reached via infected USB drives to selectively deliver reconnaissance tooling to already-compromised victims.
ExecutionOperators use Snake's built-in Run command to execute PowerShell, ping other hosts, map network drives with net use, or launch executables previously staged on the host via the implant's file-write command.
PersistenceRegisters a Windows service, typically named WerFaultSvc, that decrypts and loads Snake's components on every boot. The kernel driver provides the implant's long-term stealth advantage over user-mode-only malware.
Defense EvasionA kernel driver hides Snake's on-disk components from directory listings and mediates every request to an encrypted covert filesystem. The installer disguises itself as a JPEG viewer, Notepad++, or 7-Zip; the persistence binary is named WerFault.exe; and configuration data is stored as a high-entropy encrypted blob inside an unrelated registry key.
Credential AccessTurla deploys keyloggers, network sniffers, and open-source tools to gather user and administrator credentials for lateral movement. The advisory notes this keylogging capability persists as a risk even after Snake itself is disabled.
DiscoveryAfter establishing a foothold, operators enumerate the network, map shares and trust relationships, and work toward domain controller access before regular collection operations begin.
Lateral MovementOnce administrator credentials are obtained, operators avoid deploying additional heavyweight implants internally, relying instead on valid accounts and lightweight remote-access tools, including a long-used triggerable reverse shell as a backup access vector.
CollectionFiles, process listings, and directory contents are pulled through built-in commands (Get, List Dir, PS) and staged inside the Queue structure, itself CAST-128 encrypted, before passive exfiltration to a hop point.
Command and ControlCustom HTTP, TCP, UDP, and DNS-based protocols ride on top of legitimate application traffic. A per-implant "ustart" authentication value lets a Snake node act as a P2P server on an existing open port without opening any new one, and Forward commands chain requests through multiple hop points before reaching the FSB operator.
ExfiltrationCollected data is written to a randomly selected communication channel during Passive Operations and later retrieved by the operator through the same Queue mechanism used for inbound commands.
Recon / Priv Esc / ImpactNot documented in the CISA/FBI advisory for this Snake variant. Privilege escalation is generally achieved through obtained credentials rather than an exploited vulnerability once inside the network.
How the attack startsT1190 · T1566.001 · T1091

Initial access: exploited perimeter or hijacked legacy infrastructure

The CISA/FBI advisory does not attribute a single, repeatable initial-access exploit to the Snake variant it documents; the FSB typically deploys Snake to external-facing infrastructure nodes and works inward from there. Once a foothold is established, the FSB enumerates the network and works to obtain administrator credentials and domain controller access before deploying further tooling.

A separate, better-documented 2023 Turla operation illustrates how the group also gains access opportunistically rather than only through its own tooling. Turla re-registered at least three expired command-and-control domains belonging to ANDROMEDA, a commodity malware family that spreads via infected USB drives and was first seen in 2013. Rather than build new infrastructure, Turla profiled the existing pool of ANDROMEDA-infected hosts and selectively delivered its own Kopiluwak reconnaissance utility and QuietCanary backdoor to the victims it found interesting, reusing infrastructure defenders were unlikely to flag as a nation-state indicator.

Why this matters for defenders: a network already carrying old commodity malware is not automatically low priority. Turla's own tradecraft shows that legacy infections are actively reused as a low-visibility delivery channel for higher-value implants.

What runs on the endpointT1027.002 · T1140 · T1543.003 · T1547.006 · T1036

Installer, staging, and persistence

Snake's installer, historically named jpsetup.exe or jpinst.exe, is packed using a customized methodology built on top of unpacking code borrowed from an open-source JPEG viewer project, so the installer masquerades as ordinary image-viewing software. Other observed disguises include Notepad++ and 7-Zip. The installer requires two command-line arguments: a SHA-256-hashed string that becomes an AES key, and a second value used to derive the initialization vector. Both are needed to decrypt an embedded resource referred to as the "Png Resource," which becomes an executable called "Stage 2."

Persistence artifacts documented by CISA/FBI (AA23-129A)
Service:  WerFaultSvc  (blends with legitimate WerSvc)
Binary:   %windows%\WinSxS\...\WerFault.exe  (non-standard icon resource sizes)
Driver:   %windows%\system32\Com\comadmin.dat  (AES-encrypted kernel driver + loader)
Registry: HKLM\SOFTWARE\Classes\.wav\OpenWithProgIds  (encrypted key/IV/path blob)
Queue:    %windows%\registration\<GUID>.<GUID>.crmlog  (CAST-128 encrypted state file)

Stage 2 extracts the components that ultimately become Snake's host artifacts: a kernel driver and its custom loader, both stored AES-encrypted in a single file typically named comadmin.dat. Persistence is set through a registered Windows service, typically named WerFaultSvc, chosen specifically to resemble the legitimate WerSvc Windows Error Reporting service. On boot, this service launches Snake's own WerFault.exe, hidden among the many legitimate files of that name inside %windows%\WinSxS\, which decrypts Snake's remaining components and loads them into memory.

How the malware evades detectionT1014 · T1027 · T1564 · T1112 · T1573 · T1095

Kernel-mode concealment and protocol design

Snake's evasion advantage does not come from a single trick; it comes from architecture. The implant's kernel module removes Snake's host components from any listing returned by the operating system and mediates every request between user-mode Snake components and a concealed, encrypted storage mechanism known as the covert store: a file-backed NTFS or FAT-16 filesystem encrypted with CAST-128 using a per-implant key.

The most distinctive evasion mechanism sits at the network layer. Rather than open a new listening port, Snake's kernel module intercepts the first client-to-server packet of every TCP session on a port an existing legitimate service is already using, and checks it against a per-implant authentication value called "ustart." If the packet authenticates, the kernel module silently redirects that session to Snake's own processing logic; if not, the packet passes through to the legitimate application untouched. This means a compromised web or SSH server keeps functioning normally for everyone else while also quietly serving as a Snake P2P relay node on the same port, with no new open port to alert a port scan.

Command traffic is layered further: Snake's application-layer commands are encrypted with per-exchange CAST-128 keys wrapped in RSA-4096, riding inside a custom "enc" layer derived from a Diffie-Hellman exchange, itself riding on top of custom HTTP, TCP, UDP, or DNS transport. CISA notes the FSB's own implementation mistake — an undersized 128-bit Diffie-Hellman prime — was one of the few cryptographic weaknesses investigators were able to exploit against an otherwise carefully engineered protocol stack.

Why this matters for defenders: signature hunting for a specific file hash or IP address has a short shelf life against this design. Detection has to target structural properties of the protocol or the host artifacts that can't be relocated without breaking the implant: the covert store's encrypted filesystem header, the registry blob's entropy.

What it tries to access or modifyT1003 · T1056.001 · T1078 · T1083 · T1135 · T1482 · T1074

Credential access, network mapping, and long-term collection

Snake itself is rarely the tool that does the heavy credential harvesting. After gaining and cementing ingress, the FSB typically enumerates the network and works to obtain administrator credentials and access domain controllers, using keyloggers, network sniffers, and open-source tools deployed alongside the implant. Once domain-level credentials are in hand, operators generally stop deploying additional heavyweight implants and instead rely on those credentials plus lightweight, built-in remote-access tooling to move laterally, including a small triggerable reverse shell the FSB has used for roughly 20 years as a backup access path.

Within the implant itself, Snake's High commands give an operator direct interaction with the host: PS (0x65) lists running processes, List Dir (0x840) enumerates directory contents, Syst (0x6b) collects system information, Get (0x68) exfiltrates a file, and Put (0x69) writes one. Configuration data — including RSA and CAST keys, communication channel definitions, and the process name Snake has injected into — is tracked in an internal structure Snake's developers call the Queue.

On the network side, operators favor read access to domain trust relationships and shared drives over destructive changes. Snake's design and the FSB's operational pattern are both oriented toward long-term, low-noise intelligence collection rather than one-time disruption. Registry modification is limited almost entirely to concealing Snake's own configuration, not to tampering with victim data or settings.

Process tree

What Snake's install-to-relay chain looks like in EDR telemetry

Where Malware Protection Plus fits

Turla Snake targets Windows endpoints and is designed to evade traditional detection through encrypted components, disguised installers, and a kernel driver that hides files and processes. This makes endpoint behavioral visibility critical.

Key behavioral signals include unfamiliar services with SYSTEM-level driver-loading rights, processes allocating executable memory outside their signed images, and suspicious outbound connections using ports associated with legitimate services. These behaviors can reveal the implant even when it remains hidden from normal system listings.

Malware Protection Plus helps detect these suspicious behaviors, isolate affected endpoints to limit further spread, and support investigation using process and service telemetry. Monitoring service creation and driver-loading activity over time is particularly important for detecting long-term kernel-level persistence.

Indicators of compromise

Snake's on-disk artifacts rotate names and paths across campaigns, but several structural properties documented directly by CISA and the FBI are durable. Network infrastructure (hop-point IPs and domains) is the most volatile category here, since most of it consists of other victims' compromised servers.

File paths and artifacts

4 indicators

Typical locations and naming patterns for Snake's host components. Durable across campaigns.

  • %windows%\system32\Com\comadmin.datAES-encrypted kernel driver and loader
  • %windows%\registration\{GUID}.{GUID}.crmlogQueue file; high entropy, hidden/system/archive attributes
  • %windows%\WinSxS\...\WerFault.exePersistence binary; icon resource sizes differ from genuine WerFault.exe
  • jpsetup.exe / jpinst.exe (installer)Historical installer name; also seen disguised as Notepad++ or 7-Zip

Registry keys

2 indicators

Registry locations Snake reads or writes to conceal configuration data.

  • HKLM\SOFTWARE\Classes\.wav\OpenWithProgIdsEncrypted blob containing AES key/IV/path; entropy ≥ 7.9 in a ≥ 4KB value
  • SECURITY\Policy\Secrets\nClassname used as the covert-store decryption key in some variants

Process and memory patterns

3 patterns

Service, driver, and memory-allocation behavior that signals a Snake infection.

  • Service name "WerFaultSvc"Mimics legitimate WerSvc; audit service names that closely resemble but don't match built-in services
  • PAGE_EXECUTE_READWRITE region, base ~0x20000000, valid PE headerSignature of Snake's unobfuscated usermode component injected into a host process
  • Kernel driver load outside signed baselineDriver Signature Enforcement / HVCI logs are the durable telemetry source

Network behavior

3 patterns

Protocol-level fingerprints published directly in the CISA/FBI advisory (AA23-129A).

  • HTTP header value matching ^[0-9A-Za-z]{10}[0-9A-Za-z/+]{11}=Snake "http" protocol pattern in Cookie or arbitrary header fields
  • TCP session opening with 0x00000008 / 0x00000004 length-prefix pairsStructural fingerprint of Snake's custom TCP protocol handshake
  • DNS queries via gethostbyname with base32-like labelsSnake's low-bandwidth DNS covert channel

Infrastructure (volatile)

Rotates rapidly

Treat as short-lived context, not durable blocklist entries. Hop-point nodes are almost always other victims' compromised infrastructure.

  • Snake P2P hop-point IPs and domainsAlmost always other victims' compromised, legitimate infrastructure
  • Re-registered legacy ANDROMEDA C2 domains2023 Turla campaign; domain-specific, expires quickly
  • jpsetup.exe / comadmin.dat / WerFault.exe hashesUnique per implant due to unique encryption keys; not published in bulk by CISA

Detection guidance

CISA and the FBI publish network signatures, host-artifact locations, and a memory-analysis methodology directly in AA23-129A. Memory analysis gives the highest-confidence detection since it bypasses most of Snake's concealment layers. What defenders can detect below reflects that advisory's own stated tradeoffs.

  1. 01

    Network protocol signatures (Snake http / http2 / tcp)

    NIDS

    Suricata rules matching Snake's fixed-length header patterns in HTTP header fields and the length-prefix sequence of its custom TCP handshake, both published verbatim in the CISA/FBI advisory (AA23-129A).

    Why it works: the structural byte-length pattern is a property of the protocol itself and can't be changed without breaking implant-to-implant compatibility across the P2P network. False positive note: the advisory notes some potential for false positives on the http/http2 signatures alone; treat a hit as a lead for host-based confirmation rather than a standalone verdict.

  2. 02

    High-entropy registry blob at OpenWithProgIds

    Registry monitoring

    A registry value at or near HKLM\SOFTWARE\Classes\.wav\OpenWithProgIds exceeding roughly 4KB with entropy at or above 7.9, inconsistent with normal ProgID association data.

    Why it works: Snake's key material and paths must be stored somewhere accessible to WerFault.exe on every boot; high entropy in an otherwise low-entropy registry location is a strong tell regardless of which exact key is used in a given variant.

  3. 03

    WerFault.exe icon-resource anomaly

    File / YARA scanning

    Files named WerFault.exe under %windows%\WinSxS\ whose icon resource sizes do not match the legitimate Microsoft binary's known icon dimensions.

    Why it works: Snake's persistence binary reuses the legitimate filename to blend in among many valid copies, but the packaging process leaves a detectable difference in the PE resource section.

  4. 04

    Anomalous service creation mimicking WerSvc

    EDR / service telemetry

    New service creation events for services named similarly to, but not matching, WerSvc (for example WerFaultSvc), especially where the service binary path or loading driver falls outside the organization's signed baseline.

    Why it works: Snake needs a service to survive reboot, and reusing a near-identical name to a built-in Windows service is a durable behavioral pattern even as the exact name varies by campaign.

  5. 05

    Reflective memory injection at a fixed offset

    Memory analysis

    A PAGE_EXECUTE_READWRITE memory allocation, commonly starting near virtual address 0x20000000, containing a valid PE header not backed by any file on disk, detectable with tools such as Volatility3. CISA's advisory includes a working Volatility plugin for this exact check.

    Why it works: Snake's usermode component is not obfuscated once loaded, so memory analysis exposes it directly, bypassing the kernel driver's ability to hide it from disk-based or process-listing tools. Tradeoff: highest confidence, but memory capture and analysis is comparatively slow and harder to run at scale across a large fleet.

  6. 06

    DNS covert-channel pattern

    DNS / proxy logs

    DNS lookups issued via the gethostbyname API containing base32-style encoded prefixes before the first period, with returned A-record values used as data rather than routable addresses.

    Why it works: Snake's DNS protocol repurposes the resolved IPv4 addresses themselves as covert channel data; the encoding structure is consistent even though the destination domain and suffix are arbitrary.

Hardening recommendations

CISA and the FBI frame their mitigations as reducing the FSB's ability to persist and hide, not as blocking the initial-access vector, which varies by campaign. Items are tagged by deployment difficulty: Quick win = single policy or configuration change. Standard = needs staged rollout or infrastructure investment.

  1. Enforce Driver Signature Enforcement and memory-integrity protections

    Quick win

    Snake's persistence and concealment both depend on loading an unsigned kernel driver. Modern Windows, Linux, and macOS releases make kernel-space operation substantially harder for adversaries when these protections are enabled and enforced.

    Path: Enable Hypervisor-Protected Code Integrity (HVCI) and Driver Signature Enforcement via Group Policy or Windows Security settings; audit for driver-load events that fail signature checks.

  2. Deploy the published network signatures from AA23-129A

    Standard

    CISA and the FBI publish ready-to-use Suricata rules for Snake's http, http2, and tcp protocol patterns directly in the joint advisory AA23-129A.

    Path: Load the advisory's Suricata rule set into your NIDS/IPS; tune for false positives before moving from alert-only to blocking mode.

  3. Change credentials and enforce phishing-resistant MFA

    Quick win

    Snake's keylogger and credential-harvesting activity routinely returns logs to FSB operators. CISA recommends changing credentials from a non-compromised system if Snake activity is suspected, using values unrelated to previous passwords.

    Path: Require unique, minimum-strength credentials organization-wide (CPG 2.B/2.C) and deploy phishing-resistant MFA (CPG 2.H) to reduce the value of any credentials already stolen.

  4. Separate user and privileged accounts and segment the network

    Standard

    Turla's typical post-compromise pattern is to obtain administrator credentials and reach domain controllers using tools already present on the network rather than new heavyweight malware.

    Path: Separate user and privileged accounts (CPG 2.E) and apply default-deny network segmentation so lateral movement to domain controllers requires an explicit, monitored path (CPG 2.F).

  5. Scan internet-facing infrastructure for legacy or forgotten malware

    Standard

    Turla's 2023 ANDROMEDA operation showed the group deliberately reusing infrastructure tied to old, seemingly low-priority commodity malware to avoid detection triage.

    Path: Treat any confirmed legacy malware infection, even one considered dormant or low-severity, as a potential delivery channel; audit and remediate rather than deprioritize it.

Primary references

Source material this page is built on. Last reviewed against the CISA/FBI/NSA joint advisory and MITRE ATT&CK Turla (G0010) group page.

Test your defenses against kernel-mode, long-dwell espionage implants.

Malware Protection Plus helps security teams detect suspicious endpoint behavior, isolate compromised systems, investigate root cause, and restore affected endpoints faster.