Skip to content
Tech News
← Back to articles

Sality botnet infrastructure dismantled in joint global takedown

read original more articles
Why This Matters

The dismantling of the Sality botnet marks a significant victory in global cybersecurity efforts, disrupting a longstanding malware network responsible for widespread infections and malicious activities. This joint operation highlights the importance of international cooperation in combating sophisticated cyber threats that impact both consumers and the tech industry. It also underscores the ongoing need for advanced threat detection and proactive takedown strategies to protect digital infrastructure.

Key Takeaways

International law enforcement agencies and private partners have seized Sality malware infrastructure in a joint action aiming to disrupt and take down the peer-to-peer (P2P) botnet.

As part of this operation, the U.S. Department of Justice (DOJ), FBI, and DCIS seized Sality-linked domains in the United States, while law enforcement partners in Bulgaria, Hungary, and Romania seized additional Sality-linked domains hosted in Europe.

CrowdStrike's Counter Adversary Operations team, in collaboration with international law enforcement and private industry partners, also dismantled the botnet's control channels in a peer-to-peer sinkhole operation that isolated infected machines.

The Sality botnet has been active for more than two decades and has infected over 15,000 devices with malware since at least 2003, when it first surfaced. CrowdStrike says Sality is controlled by a criminal group it tracks as SALTY SPIDER, which is likely operating out of the Republic of Bashkortostan in Russia.

"The victim computers infected with Sality were part of a peer-to-peer (P2P) botnet, which is a network of computers (each a 'bot) infected with the Sality malware and controlled by the Sality operator," the DOJ said.

According to CrowdStrike, the two separate Sality botnet networks that were still active when the takedown took place this week were mainly used to push EggJagger malware payloads in clipjacking attacks.

Throughout its history, Sality distributed a wide variety of distinct malware families spanning credential theft, spam distribution, proxy services, network exploitation, and distributed denial-of-service (DDoS) attacks," the cybersecurity company said. "For the past eight years, the primary payload has been EggJagger, a clipjacking tool that monitors the clipboard for cryptocurrency wallet addresses and silently replaces them with addresses controlled by the operator."

Sality infected devices (CrowdStrike)

​The P2P botnet was disrupted by sinkholing Sality's list of known super peers, which form its communication backbone, to block file packs (direct payload transfers) and URL packs (payload download instructions) from propagating and purging infected machines' peer lists.

"After more than two decades of continuous operation, CrowdStrike, together with international law enforcement and industry partners, conducted a successful disruption operation against the Sality botnet, which is now no longer under the operator's control," CrowdStrike added.

... continue reading