🚨23-Year-Old Sality Botnet Disrupted by Law Enforcement
A 23-year-old botnet is finally down for the count
TL;DR
International law enforcement and CrowdStrike have disrupted the Sality botnet, which has been active since 2003. The botnet, known for stealing cryptocurrency and spreading malware, has been dismantled through a peer-to-peer sinkhole operation.
International law enforcement agencies and CrowdStrike have successfully disrupted the Sality botnet, a 23-year-old peer-to-peer network that has been active since 2003. This botnet has been responsible for distributing malicious code to over 15,000 machines worldwide and stealing at least $150,000 in cryptocurrency. The disruption was achieved through a peer-to-peer sinkhole operation that isolated infected machines, breaking the criminal operator's ability to communicate with devices on its network. This operation involved seizing Sality-linked domains and inserting purpose-built sinkhole entries into peer lists, giving police and cyber operatives visibility into the botnet's progress. The Shadowserver Foundation is working with ISPs and CSIRTs to identify infections and aid in victim notification and remediation. This is a significant win for cybersecurity and a major disruption to ongoing criminal operations.

Key Points
Sality has been active since 2003, targeting over 15,000 machines worldwide.
The botnet's primary payload, EggJagger, has stolen at least $150,000 in cryptocurrency.
The disruption involved executing a peer-to-peer sinkhole operation to isolate infected machines.
US Justice Department, FBI, and DOD's DCIS seized Sality-linked domains in the US.
International law enforcement in Bulgaria, Hungary, and Romania also took action against Sality.
Why It Matters
This disruption affects anyone who has ever been targeted by Sality. The botnet's primary payload, EggJagger, has been used to steal cryptocurrency and distribute malware. The takedown removes a significant threat to cybersecurity, especially for those who have been unknowingly infected by Sality. The Shadowserver Foundation's work with ISPs and CSIRTs to identify infections and aid in remediation is crucial for preventing further damage.
Frequently Asked Questions
Why does this matter?
This disruption affects anyone who has ever been targeted by Sality. The botnet's primary payload, EggJagger, has been used to steal cryptocurrency and distribute malware. The takedown removes a significant threat to cybersecurity, especially for those who have been unknowingly infected by Sality. The Shadowserver Foundation's work with ISPs and CSIRTs to identify infections and aid in remediation is crucial for preventing further damage.
What happened?
International law enforcement and CrowdStrike have disrupted the Sality botnet, which has been active since 2003. The botnet, known for stealing cryptocurrency and spreading malware, has been dismantled through a peer-to-peer sinkhole operation.
Comments
Be the first to comment
Enjoyed this article?
Get it daily. 7am. Free. Reads in 5 minutes.
Join 3,436 builders reading daily.