NordVPN Promotion

Home / News

International Operation Disrupts Sality Botnet After More Than Two Decades

An international law-enforcement and cybersecurity operation has disrupted Sality, a long-running peer-to-peer botnet that authorities say has been used since 2003 to distribute malware, steal cryptocurrency and support other cyberattacks.

The operation, carried out August 31, involved authorities in the United States, Bulgaria, Hungary and Romania, with support from Europol and Eurojust and technical participation from CrowdStrike and the Shadowserver Foundation. The U.S. Justice Department announced the action September 1.

More than 11 million unique IP addresses have been linked to Sality infrastructure over its lifetime. Europol said the botnet at its peak gave its operator access to as many as one million infected machines worldwide. Those figures describe historical reach rather than the number of computers under active control when the disruption occurred.

Sality’s decentralized design made it unusually difficult to disable. Unlike botnets that depend primarily on centralized command-and-control servers, infected Sality machines exchanged commands and information directly with other compromised computers. That architecture removed an obvious central point that authorities could simply seize.

The disruption turned Sality’s peer-to-peer mechanism against the botnet. CrowdStrike said it manipulated the protocol used to maintain lists of trusted peers, causing infected machines to discard legitimate Sality peers and replace them with defender-operated sinkholes. As machines became isolated, instructions for downloading or directly distributing new malicious payloads could no longer propagate through the network.

Authorities simultaneously targeted supporting Internet infrastructure. The Justice Department, FBI and Defense Criminal Investigative Service seized Sality-linked domains in the United States, while European authorities acted against additional domains. The Shadowserver Foundation is working with Internet service providers and computer security incident response teams to identify infected systems, notify affected parties and support remediation.

The action disrupts Sality’s control infrastructure but does not itself remove malware from infected computers. CrowdStrike said more than 15,000 machines were receiving malicious payloads through the network immediately before the operation. Shadowserver’s notification and remediation work is therefore an important second stage: compromised systems can remain infected even after their connection to the botnet operator has been severed.

The operation also illustrates the challenge posed by decentralized botnets. Sality’s peer-to-peer architecture helped it survive for more than two decades without depending on a single command server, requiring investigators and security researchers to intervene at the protocol and infrastructure levels rather than rely on a conventional server seizure.

NORDVPN DISCOUNT - CircleID x NordVPN
Get NordVPN  [74% +3 extra months, from $2.99/month]
By CircleID Reporter

CircleID’s internal staff reporting on news tips and developing stories. Do you have information the professional Internet community should be aware of? Contact us.

Visit Page

Filed Under

Comments

Comment Title:

  Notify me of follow-up comments

We encourage you to post comments and engage in discussions that advance this post through relevant opinion, anecdotes, links and data. If you see a comment that you believe is irrelevant or inappropriate, you can report it using the link at the end of each comment. Views expressed in the comments do not represent those of CircleID. For more information on our comment policy, see Codes of Conduct.

CircleID Newsletter The Weekly Wrap

More and more professionals are choosing to publish critical posts on CircleID from all corners of the Internet industry. If you find it hard to keep up daily, consider subscribing to our weekly digest. We will provide you a convenient summary report once a week sent directly to your inbox. It's a quick and easy read.

Related

Topics

DNS

Sponsored byDNIB.com

Brand Protection

Sponsored byCSC

Cybersecurity

Sponsored byVerisign

New TLDs

Sponsored byRadix

IPv4 Markets

Sponsored byIPv4.Global

DNS Security

Sponsored byWhoisXML API

Domain Names

Sponsored byVerisign

NordVPN Promotion