
Global operation dismantles Sality botnet after two decades
US and European agencies, with CrowdStrike, dismantle the Sality botnet, a Russian-linked cybercrime network active since 2003.
A two-decade-old Russian-linked cybercrime network known as Sality has been dismantled in a coordinated global operation, US law enforcement and cybersecurity firm CrowdStrike announced on Tuesday.
The operation, which involved the FBI, the US Justice Department, and European law enforcement agencies, saw the seizure of web domains used by hackers to control compromised computers. These machines were used to send spam, launch distributed denial-of-service attacks, and steal cryptocurrency.
CrowdStrike began the technical takedown on Monday at its Day Zero threat intelligence summit in Las Vegas. The company said it successfully cut off the network of infected computers from the mastermind controlling it.
Sality, first detected in 2003, has been one of the internet's longest-running cybercriminal enterprises. Its peer-to-peer architecture made it highly resilient, as it could receive commands through a diffuse network of compromised machines, making it difficult for law enforcement to disrupt.
CrowdStrike turned this strength against the botnet by seeding the network with bogus information, tricking its components into disconnecting from their creator. Tillmann Werner, a CrowdStrike researcher, described it as the most complex botnet takeover the company has ever performed, noting the network was built to survive takedown attempts.
David Watson of The Shadowserver Foundation, which also participated, said Sality was "quite old-school" but remained a dangerous entry point into many organizations. The next step, he said, is to see whether the botnet's unidentified creator attempts to regain control or rebuild the network.