A history of Turla, an APT that is the “premiere espionage tool” of Russia's FSB, in operation for 25+ years, with its Snake malware in use for nearly 20 years
From USB worms to satellite-based hacking, Russia's FSB hackers, known as Turla, have spent 25 years distinguishing themselves as “adversary number one.” LinkedIn: Andy Greenberg LinkedIn: Andy Greenberg : After last week's news of an FBI operation against the Russian hacker group Turla, I tried to sketch out the 25-year history of these elite FSB cyberspies …
Context & Ripple Effects
The FBI operation against Turla lands on top of a quarter-century research arc: researchers first surfaced clues about the then-20-year-old group in 2017, and Kaspersky had earlier exposed how it hijacked satellite-based Internet links to hide its whereabouts. The group's signature move is camouflage rather than novelty.
Mandiant's January 2023 report showed Turla piggybacking on another hacker group's decade-old USB-spread malware for stealth network access, and Microsoft and Lumen's Black Lotus Labs later found it running attacks off servers belonging to Pakistan-based hackers. Andy Greenberg's history ties those threads together into a portrait of the FSB's self-described "adversary number one."
First-order effects
- The FBI's operation directly targets Turla's nearly two-decade-old Snake implant infrastructure, degrading the FSB unit's access to compromised networks right now.
- Victim organizations and threat-intel teams gain a consolidated 25-year map of Turla tradecraft — USB worms, satellite relays, borrowed malware — to hunt against.
Second-order effects
- With its own toolchain under pressure, Turla is positioned to lean harder on laundered infrastructure — the piggybacked USB malware Mandiant documented and the third-party servers Black Lotus Labs traced — making attribution harder for defenders.
- Western agencies' playbook against Turla sets a template they have applied to sibling Russian units like Fancy Bear, whose Linux malware Drovorub NSA and FBI exposed in 2020.
Third-order effects
- If the pattern holds, great-power cyberespionage consolidates around state units that survive takedowns by hiding inside other actors' malware and infrastructure, forcing attribution to become a multi-vendor forensic exercise.
- Two-decade persistence of tools like Snake points toward espionage being treated as permanent infrastructure by nation-states — countered not with one-time cleanup but recurring coordinated disruption operations by agencies like the FBI.
The trend: Russia's FSB cyberespionage is proving durable across decades by recycling other hackers' tools and infrastructure, while US agencies respond with repeated public unmaskings and infrastructure takedowns.