Particle.news

Global Operation Disrupts Sality Botnet After 23 Years

Isolating infected peers through protocol-level manipulation cut the operator’s control and seized hosting domains, leaving cleanup of compromised machines and legal follow-up as the next tasks.

Overview

  • CrowdStrike, the U.S. Department of Justice, the FBI and partners in Bulgaria, Hungary and Romania ran a coordinated action that seized Sality-linked domains and redirected infected machines to defender-operated sinkholes.
  • The technical takedown used peer-list manipulation to exploit Sality’s lack of peer authentication so bots removed legitimate super peers and began beaconing to CrowdStrike-controlled servers.
  • CrowdStrike and partners say the move, demonstrated live at the company’s Day Zero summit, isolated more than 15,000 infected machines and stopped the botnet from receiving new payloads.
  • For the past eight years Sality mainly delivered EggJagger, a clipboard-hijacking tool that CrowdStrike estimates stole at least 12.1 million rubles (about $150,000) and left larger unspent holdings that later rose in value.
  • The disruption does not remove malware from infected endpoints, so Shadowserver, ISPs and national CSIRTs are notifying victims and guiding remediation while investigators continue work to attribute and pursue the operator.