Ethical Hacking News
International law enforcement agencies, CrowdStrike, and Shadowserver Foundation have successfully disrupted a 23-year-old peer-to-peer botnet known as Sality, which has been used to deliver malware to over 15,000 machines worldwide. The operation targeted the botnet's network awareness by isolating infected machines and inserting purpose-built sinkhole entries into peer lists, effectively breaking the botnet.
The 23-year-old Sality botnet was disrupted in a major victory in the fight against cybercrime, involving international law enforcement agencies, CrowdStrike, and the Shadowserver Foundation. Sality, a peer-to-peer botnet, has been responsible for various malicious activities, including credential theft, spam distribution, and DDoS attacks. The operation targeted Sality's peer list, isolating infected machines and inserting sinkhole entries to gain visibility into the operation's progress. The success of the operation was largely due to the work of CrowdStrike's Counter Adversary Operations team, which has expertise in identifying and disrupting complex networks. The disruption also saw the seizure of Sality-linked domains in the US and Europe, with international law enforcement agencies taking action against additional domains. The operation highlights the importance of collaboration, innovation, and education in preventing cybercrime, and serves as a reminder that the battle against cybercrime is ongoing.
The world of cybersecurity has seen its fair share of high-profile botnet operations in recent years, but the recent disruption of the 23-year-old Sality botnet stands out as a significant victory in the ongoing battle against cybercrime. This operation, which involved international law enforcement agencies, CrowdStrike, and the Shadowserver Foundation, marks a major milestone in the fight against Sality, a peer-to-peer botnet that has been used to deliver malware to over 15,000 machines worldwide.
Sality, which has been in operation since 2003, has been responsible for a wide range of malicious activities, including credential theft, spam distribution, proxy services, network exploitation, and distributed denial-of-service (DDoS) attacks. One of the most notorious payloads associated with Sality is EggJagger, a tool that monitors clipboards for cryptocurrency wallet addresses and then silently replaces them with attacker-controlled addresses. This has allowed criminals to steal millions of dollars in cryptocurrency, with estimates suggesting that the operator of Sality has stolen at least $150,000 in cryptocurrency using EggJagger alone.
The operation to disrupt Sality was carried out by CrowdStrike's Counter Adversary Operations team, which worked in conjunction with international law enforcement agencies and industry partners to target the botnet's network awareness. The team's approach was to isolate infected machines by removing legitimate super peers from each bot's peer list, and then inserting purpose-built sinkhole entries into peer lists. This approach allowed police and cyber operatives to gain visibility into the operation's progress and notify victims.
According to the technical writeup provided by CrowdStrike, the operation targeted the data structure at the heart of every bot's network awareness: its peer list. Each Sality bot maintains a list of known super peers – publicly reachable infected machines that form the backbone of the P2P network. Every 40 minutes, the bots check to see if their peers are still online. Peers that fail to respond are purged from the network.
The success of the operation was largely due to the work of the CrowdStrike Counter Adversary Operations team, which has been at the forefront of developing and implementing innovative countermeasures against botnets. The team's expertise in identifying and disrupting complex networks has been invaluable in this operation, and their work has helped to bring an end to decades of malicious activity by Sality.
In addition to the disruption of Sality, the operation also saw the seizure of Sality-linked domains in the US by the US Justice Department, FBI, and Department of Defense Office of Inspector General's Defense Criminal Investigative Service. International law enforcement in Bulgaria, Hungary, and Romania also took action against additional Sality-linked domains hosted in Europe.
The Shadowserver Foundation, which worked closely with CrowdStrike and international law enforcement agencies, has also played a crucial role in this operation. The organization's expertise in identifying and mitigating malware infections has been invaluable in this operation, and their work has helped to aid in victim notification and remediation.
The disruption of Sality marks a significant victory in the fight against cybercrime, and highlights the importance of collaboration and cooperation between law enforcement agencies, cybersecurity professionals, and industry partners. It also underscores the need for continued innovation and investment in cybersecurity technologies, as well as the importance of education and awareness in preventing cybercrime.
As the world of cybersecurity continues to evolve, it is clear that the disruption of Sality is just the beginning. There will likely be other botnets and malware threats in the future, and it is essential that we are prepared to respond to these threats with the same level of expertise and cooperation as we have in the case of Sality.
In conclusion, the disruption of the 23-year-old Sality botnet is a significant victory in the fight against cybercrime, and highlights the importance of collaboration, innovation, and education in preventing cyber threats. It is a reminder that the battle against cybercrime is ongoing, and that we must remain vigilant and proactive in our efforts to protect ourselves and our communities from these threats.
Related Information:
https://www.ethicalhackingnews.com/articles/Cops-CrowdStrike-and-Shadowserver-Foundation-Disrupt-23-Year-Old-Sality-Botnet-Bringing-an-End-to-Decades-of-Malicious-Activity-ehn.shtml
https://www.theregister.com/cyber-crime/2026/09/02/cops-crowdstrike-disrupt-sality-botnet-by-poisoning-the-network-and-diverting-into-sinkholes/5293795
Published: Tue Sep 1 19:53:42 2026 by llama3.2 3B Q4_K_M