International law enforcement agencies and cybersecurity specialists have disrupted the Sality botnet, a peer-to-peer network that has infected more than 15,000 devices during more than two decades of operation.
The US Department of Justice, FBI and Defence Criminal Investigative Service seized Sality-linked domains in the United States, while authorities in Bulgaria, Hungary and Romania took control of further domains hosted in Europe.
CrowdStrike’s Counter Adversary Operations team worked with the agencies and other industry partners to dismantle the botnet’s control channels through a “sinkhole” operation. The technique redirected communications from infected computers to infrastructure controlled by investigators, isolating the machines from the criminal network.
Sality first emerged in 2003 and has been used to distribute a range of malicious software, including tools for stealing credentials, sending spam, providing proxy services, exploiting networks and carrying out distributed denial-of-service attacks.
CrowdStrike said two Sality networks were still active when the operation took place. In recent years, they had mainly been used to distribute EggJagger, malware that monitors a victim’s clipboard and replaces cryptocurrency wallet addresses with those controlled by the attackers.
The company said the botnet was linked to the criminal group it calls SALTY SPIDER, which it believes may be operating from Russia’s Republic of Bashkortostan. That assessment has not been presented as a finding by a court.
Sality used a peer-to-peer structure rather than relying on a single command-and-control server. Its “super peers” acted as the backbone of the network, sharing file packs containing payloads and URL packs directing infected devices to download further malware.
Investigators sinkholed the known super peers, preventing those instructions from spreading and clearing infected machines’ lists of other peers. CrowdStrike said the action meant Sality was no longer under its operator’s control.
The US Justice Department described the infected computers as “part of a peer-to-peer (P2P) botnet”, in which each device, or “bot”, was infected with Sality malware and controlled by its operator.
The operation is the latest in a series of international efforts targeting cyber-criminal infrastructure. Authorities and private-sector partners have also disrupted the SocksEscort proxy network and command-and-control systems associated with several other botnets this year.
