Particle.news

Global Operation Cuts Off Sality Botnet Operator

Operators have been cut off from the network, requiring infected device owners to remove persistent malware before systems are secure again.

Overview

  • CrowdStrike and U.S. law enforcement led a coordinated takedown that seized Sality-linked domains and sinkholed the botnet so infected machines now report to defender-run nodes.
  • CrowdStrike began the technical sinkhole operation on Monday, August 31, using protocol-level peer-list manipulation to replace super peers with sinkholes and isolate bots.
  • Sality is a 23-year-old peer-to-peer file-infector that infected more than 15,000 machines and for about eight years mainly delivered the EggJagger clipboard hijacker that CrowdStrike estimates stole at least 12.1 million rubles (roughly $150,000).
  • U.S. authorities (DOJ, FBI, DCIS) worked with partners in Bulgaria, Hungary and Romania plus the Shadowserver Foundation to seize payload hosting URLs and coordinate victim notification and cleanup efforts.
  • The operator cluster tracked as SALTY SPIDER is assessed to operate from Russia’s Bashkortostan region and has not been publicly identified for prosecution; defenders warn that existing malware remains active and requires manual removal by owners or IT teams.