Particle.news

International Operation Cuts Off Sality Botnet Operator

The takedown severed the operator’s live control through protocol-level manipulation and domain seizures, yet infected machines still need manual cleanup by owners and ISPs.

Overview

  • Law enforcement and private partners carried out the disruption in a coordinated action that began on Monday, using domain seizures and a peer-to-peer sinkhole to isolate the network from its controller.
  • CrowdStrike and partners exploited Sality’s peer-list trust flaw to inject defender-run nodes that cause infected machines to beacon to a lighthouse IP instead of the operator.
  • Authorities seized Sality-linked domains in the United States and in Europe through actions by the DOJ, FBI and partners in Bulgaria, Hungary and Romania to block payload hosting.
  • All infected hosts now contact CrowdStrike-operated sinkholes at IP 188.166.101.148, which prevents new payloads but does not remove malware already installed on those machines.
  • Sality has run since about 2003, infected an estimated 15,000+ devices, delivered clipper malware that stole cryptocurrency and supported DDoS campaigns, and victims and ISPs must now detect and remove residual infections.