/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

A history of Turla, an APT that is the “premiere espionage tool” of Russia's FSB, in operation for 25+ years, with its Snake malware in use for nearly 20 years

From USB worms to satellite-based hacking, Russia's FSB hackers, known as Turla, have spent 25 years distinguishing themselves as “adversary number one.” LinkedIn: Andy Greenberg LinkedIn: Andy Greenberg : After last week's news of an FBI operation against the Russian hacker group Turla, I tried to sketch out the 25-year history of these elite FSB cyberspies …

Wired Andy Greenberg

Context & Ripple Effects

The FBI operation against Turla lands on top of a quarter-century research arc: researchers first surfaced clues about the then-20-year-old group in 2017, and Kaspersky had earlier exposed how it hijacked satellite-based Internet links to hide its whereabouts. The group's signature move is camouflage rather than novelty.

Mandiant's January 2023 report showed Turla piggybacking on another hacker group's decade-old USB-spread malware for stealth network access, and Microsoft and Lumen's Black Lotus Labs later found it running attacks off servers belonging to Pakistan-based hackers. Andy Greenberg's history ties those threads together into a portrait of the FSB's self-described "adversary number one."

First-order effects

  • The FBI's operation directly targets Turla's nearly two-decade-old Snake implant infrastructure, degrading the FSB unit's access to compromised networks right now.
  • Victim organizations and threat-intel teams gain a consolidated 25-year map of Turla tradecraft — USB worms, satellite relays, borrowed malware — to hunt against.

Second-order effects

  • With its own toolchain under pressure, Turla is positioned to lean harder on laundered infrastructure — the piggybacked USB malware Mandiant documented and the third-party servers Black Lotus Labs traced — making attribution harder for defenders.
  • Western agencies' playbook against Turla sets a template they have applied to sibling Russian units like Fancy Bear, whose Linux malware Drovorub NSA and FBI exposed in 2020.

Third-order effects

  • If the pattern holds, great-power cyberespionage consolidates around state units that survive takedowns by hiding inside other actors' malware and infrastructure, forcing attribution to become a multi-vendor forensic exercise.
  • Two-decade persistence of tools like Snake points toward espionage being treated as permanent infrastructure by nation-states — countered not with one-time cleanup but recurring coordinated disruption operations by agencies like the FBI.

The trend: Russia's FSB cyberespionage is proving durable across decades by recycling other hackers' tools and infrastructure, while US agencies respond with repeated public unmaskings and infrastructure takedowns.