ZeroHour
CyberScooppublished ()ingested Matt Kapko

Dogged Russia-based botnet dismantled after 23-year run

highMalwareimportance 72
AI summary · glm-5.3-flash

Law enforcement, CrowdStrike and Shadowserver dismantled the 23-year-old Sality P2P botnet that infected more than 11 million devices.

Sality, a Russia-based peer-to-peer botnet active for 23 years and infecting over 11 million devices, was dismantled by law enforcement working with CrowdStrike and the Shadowserver Foundation. CrowdStrike poisoned the botnet's peer list so infected machines permanently disappeared from the operator's view, while domains were seized in a coordinated effort involving the FBI, Justice Department, Europol and authorities from Bulgaria, Hungary and Romania. The financially motivated operation enabled cryptocurrency theft, DDoS attacks and other cyberattacks, and Europol said the effort dates back to 2017; the operators were not named.

  • Decentralized P2P architecture let Sality evade disruption for over two decades
  • CrowdStrike tricked the network into severing infected peers, making the botnet irrecoverable
  • Shadowserver is working with ISPs to identify and remediate infected devices
  • Attributed three DDoS attacks to the botnet alongside its criminal use
Full article608 words · extracted from cyberscoop.com · click to collapse

Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

Sality’s peer-to-peer infrastructure allowed it to evade system-wide disruption efforts for an exceptionally long period. Authorities and cybersecurity experts finally brought it down.

Listen to this article

0:00

Learn more.

(Getty Images)

Sality, a Russia-based botnet that infected more than 11 million devices during a 23-year run of operations, was dismantled Monday by law enforcement, CrowdStrike and the Shadowserver Foundation.

CrowdStrike, which announced the takedown Tuesday alongside authorities, said it played a crucial role dismantling the botnet’s technical infrastructure, rendering the malware-spreading operation irrecoverable.

The peer-to-peer botnet was a persistent piece of criminal infrastructure that evaded disruption for an exceptionally long period because it lacked centralized architecture.

Sality used infected machines to communicate peer-to-peer, creating a decentralized structure that made system-wide disruption efforts more difficult than botnets that rely on a core server.

“The same properties that made Sality resilient also created the conditions for its undoing,” CrowdStrike wrote in a blog post. The company said it targeted Sality’s peer list of infected machines and tricked the network into permanently cutting off access to those devices.

“From the operator’s perspective, infected machines simply disappear,” CrowdStrike wrote, adding that the botnet is no longer under the operator’s control.

Sality’s domains were seized by a globally coordinated effort supported by the FBI, Justice Department and authorities from Europol , Bulgaria, Hungary and Romania, officials said. Shadowserver is working with internet service providers to identify devices infected by Sality and aid with remediation.

“Cybercriminals, botnets, and malware are a clear and present danger to our nation’s security and economy,” Bill Essayli, first assistant U.S. attorney, said in a statement.

Europol said the Sality takedown was the culmination of work spanning global law enforcement back to 2017.

CrowdStrike said Sality’s operator was primarily financially motivated, but it attributed three DDoS attacks to Sality, suggesting the operator was occasionally willing to use the botnet for personal or political aims.

The botnet enabled cryptocurrency theft and cyberattacks on victims in the United States and abroad, the Justice Department said. Officials did not name the person or cybercrime group behind Sality.

“This operation demonstrates that peer-to-peer architecture, long considered a shield against disruption, is not invincible,” CrowdStrike wrote.

“Operating for decades without consequence does not mean operating without risk,” the company added. “The calculus has changed. We will find you, we will dismantle your infrastructure, and we will impose costs that make the enterprise untenable.”

Latest Podcasts

Government

The G7 tells industry to hurry up and prep for post-quantum encryption

FCC proposes public scorecard to rate telecoms on anti-robocall efforts

Tina Peters, through attorney, backs off formal role in Shasta County elections

Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots

Technology

Pegasus, NoviSpy variant spyware found on devices of Serbian activists

Wyden seeks upgraded NSA security guidance on commercial VPN use

The Collective Cyber Defense letter wrote your next vendor questionnaire

Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities

Threats

‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help

ATF confirms cyberattack hit system containing info on its investigation targets

Unit 42 warns AI has shifted balance of power from defenders to attackers

Two alleged TeamPCP members arrested and charged after months of software supply-chain chaos

Policy

Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure

Election official says Tina Peters would be consultant, won’t have access to election systems

Bipartisan Senate bill aims to prepare energy sector for Q-Day

Postal Service moves to finalize mail ballot regs before SCOTUS ruling

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/sality-botnet-dismantled/