After 23 years of operation, the Sality peer-to-peer (P2P) botnet has been disrupted as part of an international law enforcement effort.
First observed in 2003, Sality has been used for distributing various malware families, including information stealers, proxy services, distributed denial-of-service (DDoS) payloads, and more.
For the past eight years, it mainly served the EggJagger clipjacking tool, which is believed to have stolen at least $150,000 in Bitcoin and Ethereum.
Sality remained active due to its architecture: it spread through a file infector, attaching itself to executables on disk and removable media, and did not rely on a central command-and-control (C&C) server for receiving code updates.
The protocol behavior that allowed the botnet to persist for over 20 years was also the weakness that led to its demise: it blindly trusted the peers on the network, without authentication or identity verification.
Sality bots periodically checked if the peers in their list of super peers (infected machines forming the backbone of the P2P network) were accessible. Those that were online built reputation, while those offline lost it and were eventually purged.
Exploiting this behavior, CrowdStrike performed protocol-level manipulation of the list, removing the super peer entries to progressively isolate infected machines, while injecting sinkholes into the list.
Coordinating with CrowdStrike’s bot isolation and P2P network sinkholing, law enforcement in the US, Bulgaria, Hungary, and Romania took down the URLs hosting Sality payloads, ensuring that the infected machines would not receive new payloads.
“The criminal behind Sality has lost the ability to communicate with infected machines. The disruption operation isolates all peers in the network from their control. […] All Sality-infected machines now beacon to CrowdStrike-operated sinkholes,” CrowdStrike notes .
As part of the disruption effort, The Shadowserver Foundation is working with ISPs and CSIRTs to identify botnet victims and clean up the infections.
Related: Five Venezuelans Plead Guilty in US Court to ATM Jackpotting
Related: US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks
Related: Pro-Russian Hackers Claim Responsibility for Major Cyberattack on Norway’s Public Digital Services
Related: Google, FBI Disrupt NetNut Residential Proxy Network Powered by Millions of Devices
US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks
The operation focused on a group named QTFY, which offers hacking services to the Chinese government and others.
First Malware Built Specifically for Car Head Units Fuels Botnet
Kaspersky researchers have linked the malware to the BadBox botnet, which has ensnared millions of devices.
Microsoft and Allies Smash Shared Infrastructure of Amadey and StealC Malware
Hundreds of C&C servers were disrupted in an operation involving law enforcement and several cybersecurity companies.
15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown
Law enforcement and private partners took down 106 SocGholish C&C servers and domains as part of Operation Endgame.
FBI, Google Dismantle ‘Outsider Enterprise’ Phishing Service
The platform used more than 9,000 phishing sites, stealing nearly 4 million credit cards and causing roughly $1.9 billion in losses.
Over 1.4 Million Accounts Disrupted in Cybercrime Crackdown
Law enforcement and tech companies disrupted infrastructure linked to scammers operating across Southeast Asia.
Dutch Police Dismantle Massive 17-Million-Device Botnet
Dutch authorities seized command-and-control servers tied to a botnet of infected computers, smartphones, and tablets that was allegedly used to power a residential proxy...
GlassWorm Botnet Disrupted
Security firms took down all four command-and-control (C&C) channels used by the GlassWorm malware.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
