Overview
- Law enforcement and private partners carried out the disruption in a coordinated action that began on Monday, using domain seizures and a peer-to-peer sinkhole to isolate the network from its controller.
- CrowdStrike and partners exploited Sality’s peer-list trust flaw to inject defender-run nodes that cause infected machines to beacon to a lighthouse IP instead of the operator.
- Authorities seized Sality-linked domains in the United States and in Europe through actions by the DOJ, FBI and partners in Bulgaria, Hungary and Romania to block payload hosting.
- All infected hosts now contact CrowdStrike-operated sinkholes at IP 188.166.101.148, which prevents new payloads but does not remove malware already installed on those machines.
- Sality has run since about 2003, infected an estimated 15,000+ devices, delivered clipper malware that stole cryptocurrency and supported DDoS campaigns, and victims and ISPs must now detect and remove residual infections.