Operation MEDUSA
Verified core entry, last reviewed August 21, 2026
What was taken down?
Snake implants on victim machines disabled by issuing commands that caused the malware to overwrite its own vital components; peer-to-peer network neutralized.[1][2]
See what happenedWhat happened to the people?
No individual outcomes are recorded against this entry.
Group accounted for: Not applicable
Did it stay down?
After this action later activity was recorded, though its link to the original is not established. Medium confidence in the link between the two.
See what happened afterwardThe FBI executed a court-authorized operation using a purpose-built tool called PERSEUS to command Snake implants, attributed to Russian FSB Center 16, to overwrite their own components on infected machines worldwide.[1][2]
Announced May 9, 2023.
- Date
- May 2023
- Target
- Snake malware network, state espionage implant network
- Activity
- State sponsored, Malware and botnets
- Operational lead
- FBI
- Jurisdiction
- United States, United Kingdom, Canada, Australia, and New Zealand
- Outcome
- Snake implants on victim machines disabled by issuing commands that caused the malware to overwrite its own vital components; peer-to-peer network neutralized.
- Status
- Completed
- Legal mechanism
- Rule 41 search warrant, Eastern District of New York
- Group accounted for
- Not applicable
Infrastructure
Malware installations remediated and command and control servers disabled, with no count in the record.
| Identifier | Recorded as | Status | Notes |
|---|---|---|---|
| Not published | Malware installation | Remediated | Snake implants commanded to overwrite their own vital components using the FBI-developed PERSEUS tool. Exact implant count not published.[1] |
| Not published | Command and control server | Disabled | Peer-to-peer network used to relay collected data neutralized.[1] |
Domains and onion addresses are shown defanged. Where the record gives a count but no identifier, the count is shown in place of one. This list carries only what appears in the cited sources.
No individual is named against this entry in the cited record. That is a gap in what has been published rather than a finding that nobody was involved.
Group accounted for: Not applicable
The operator is a state intelligence service. A criminal operator roster is not a meaningful denominator.
State intelligence unit rather than a finite criminal operator group.
No arrests. US officials expressed confidence the network could not be readily reconstituted.[1][2]
-
Date not established
No documented return. Relationship not established. Confidence: Medium. Not established.[1]
No affirmative evidence of a Snake network reconstitution was found through the research cutoff. US officials expressed confidence the network could not be readily rebuilt.
Date not established
No documented return. Relationship not established. Confidence: Medium. Not established.[1]
No affirmative evidence of a Snake network reconstitution was found through the research cutoff. US officials expressed confidence the network could not be readily rebuilt.
Return class F. The class is a research grading carried in the source dataset and its scale is not published, so this page relies on the relationship and confidence values instead. How this index handles it.
Numbered markers throughout this entry link to the source that supports the claim beside them.
Official sources
-
[1]
Justice Department Announces Court-Authorized Disruption of Snake Malware Network Controlled by Russia's Federal Security Service
PERSEUS tool, Rule 41 warrant in EDNY, self-overwrite mechanism, FSB Center 16 attribution
-
[2]
Hunting Russian Intelligence 'Snake' Malware, joint cybersecurity advisory
Technical description of Snake and its network
- Snake had been in use for roughly twenty years across more than 50 countries.
- Charged and apprehended counts of 0 are explicitly established by DOJ.