Skip to main content
Back to the takedown index

Operation MEDUSA

May 2023, State sponsored
Led by Federal Bureau of Investigation

Verified core entry, last reviewed August 21, 2026

What was taken down?

Snake implants on victim machines disabled by issuing commands that caused the malware to overwrite its own vital components; peer-to-peer network neutralized.[1][2]

See what happened

What happened to the people?

No individual outcomes are recorded against this entry.
Group accounted for: Not applicable

See people and accountability

Did it stay down?

After this action later activity was recorded, though its link to the original is not established. Medium confidence in the link between the two.

See what happened afterward

The FBI executed a court-authorized operation using a purpose-built tool called PERSEUS to command Snake implants, attributed to Russian FSB Center 16, to overwrite their own components on infected machines worldwide.[1][2]

Announced May 9, 2023.

Date
May 2023
Target
Snake malware network, state espionage implant network
Activity
State sponsored, Malware and botnets
Operational lead
FBI
Partners
USAO-EDNY, CISA[1][2]
Jurisdiction
United States, United Kingdom, Canada, Australia, and New Zealand
Outcome
Snake implants on victim machines disabled by issuing commands that caused the malware to overwrite its own vital components; peer-to-peer network neutralized.
Status
Completed
Legal mechanism
Rule 41 search warrant, Eastern District of New York
Group accounted for
Not applicable

Infrastructure

Malware installations remediated and command and control servers disabled, with no count in the record.

Identifier Recorded as Status Notes
Not published Malware installation Remediated Snake implants commanded to overwrite their own vital components using the FBI-developed PERSEUS tool. Exact implant count not published.[1]
Not published Command and control server Disabled Peer-to-peer network used to relay collected data neutralized.[1]

Domains and onion addresses are shown defanged. Where the record gives a count but no identifier, the count is shown in place of one. This list carries only what appears in the cited sources.

No individual is named against this entry in the cited record. That is a gap in what has been published rather than a finding that nobody was involved.

Group accounted for: Not applicable

The operator is a state intelligence service. A criminal operator roster is not a meaningful denominator.

State intelligence unit rather than a finite criminal operator group.

See the organizations and roles behind this action

No arrests. US officials expressed confidence the network could not be readily reconstituted.[1][2]

  1. Date not established

    No documented return. Relationship not established. Confidence: Medium. Not established.[1]

    No affirmative evidence of a Snake network reconstitution was found through the research cutoff. US officials expressed confidence the network could not be readily rebuilt.

Date not established

No documented return. Relationship not established. Confidence: Medium. Not established.[1]

No affirmative evidence of a Snake network reconstitution was found through the research cutoff. US officials expressed confidence the network could not be readily rebuilt.

Return class F. The class is a research grading carried in the source dataset and its scale is not published, so this page relies on the relationship and confidence values instead. How this index handles it.

Numbered markers throughout this entry link to the source that supports the claim beside them.

Official sources

  1. [1]
    Justice Department Announces Court-Authorized Disruption of Snake Malware Network Controlled by Russia's Federal Security Service

    United States Department of Justice, May 9, 2023, Source grade P1

    PERSEUS tool, Rule 41 warrant in EDNY, self-overwrite mechanism, FSB Center 16 attribution

    No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

  2. [2]
    Hunting Russian Intelligence 'Snake' Malware, joint cybersecurity advisory

    Cybersecurity and Infrastructure Security Agency, May 9, 2023, Source grade P2

    Technical description of Snake and its network

    No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

Coverage note.
  • Snake had been in use for roughly twenty years across more than 50 countries.
  • Charged and apprehended counts of 0 are explicitly established by DOJ.