Breaking
Cyber CrimeDeveloping Story

Two-Decade Botnet Finally Falls

Global joint operation seizes Sality infrastructure, dismantling a botnet active since 2003.

··2 hours ago·2 min read
black laptop computer turned on with green screen
Photo by Moritz Erken on Unsplash

The Sality botnet, a sprawling peer-to-peer malware network that has operated largely unchecked for more than twenty years, has been disrupted in a coordinated international operation. Law enforcement agencies and private cybersecurity firms joined forces this week to seize infrastructure and sinkhole control channels, effectively prying the botnet from its operators' grasp.

Coordinated Seizures

As part of the action, supported by Europol and Eurojust, the U.S. Department of Justice (DOJ), FBI, and DCIS seized Sality-linked domains in the United States. Authorities in Bulgaria, Hungary, and Romania seized additional Sality-linked domains hosted in Europe, according to reports.

CrowdStrike's Counter Adversary Operations team, working alongside international law enforcement and private industry partners, dismantled the botnet's control channels in a peer-to-peer sinkhole operation that isolated infected machines.

Two Decades of Infection

Since surfacing in 2003, Sality has infected over 15,000 devices with malware. CrowdStrike attributes the botnet to a criminal group it tracks as SALTY SPIDER, which it says is likely operating out of the Republic of Bashkortostan in Russia.

The botnet's longevity is a testament to its resilient architecture. Unlike traditional botnets that rely on central command servers, Sality uses a peer-to-peer model where every infected machine serves as both a node and a potential controller, making takedowns particularly challenging.

Evolution of Payloads

"Throughout its history, Sality distributed a wide variety of distinct malware families spanning credential theft, spam distribution, proxy services, network exploitation, and distributed denial-of-service (DDoS) attacks," CrowdStrike said. "For the past eight years, the primary payload has been EggJagger, a clipjacking tool that monitors the clipboard for cryptocurrency wallet addresses and silently replaces them with addresses controlled by the operator."

Sinkhole Strategy

The disruption was achieved by sinkholing Sality's list of known super peers, which form its communication backbone. This blocked file packs—direct payload transfers—and URL packs—payload download instructions—from propagating, and purged infected machines' peer lists.

"After more than two decades of continuous operation, CrowdStrike, together with international law enforcement and industry partners, conducted a successful disruption operation against the Sality botnet, which is now no longer under the operator's control," the cybersecurity company added.

Broader Crackdown

This takedown is part of a wider pattern of increased law enforcement activity against cybercrime infrastructure. In March, American and European authorities, along with private partners, disrupted the SocksEscort cybercrime proxy network and took down Command and Control (C2) infrastructure used by the Aisuru, KimWolf, JackSkid, and Mossad botnets.

More recently, Dutch authorities took a massive botnet of 17 million devices offline in May, and an FBI-led operation disrupted the QScan and QTRouter hacking platforms used by Chinese cyber-espionage groups.

What This Means for You

For the average internet user, the disruption of Sality is a significant blow to a persistent threat that has enabled a range of criminal activities, from credential theft to cryptocurrency heists. While the botnet is no longer under the operator's control, infected machines may still harbor remnants of the malware, and users are advised to ensure their systems are clean.

This operation also signals a growing willingness among international agencies to collaborate on long-standing threats, suggesting that even the most entrenched botnets are not immune to coordinated action.

#sality#botnet#takedown#law-enforcement#crowdstrike

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories