U.S. and European law enforcement agencies, in cooperation with CrowdStrike and private-sector partners, announced the disruption of the infrastructure of the Sality botnet in an international operation targeting a malware network active for more than two decades. CrowdStrike said the network was no longer under its operators’ control after the operation, but that does not automatically mean that the malware was removed from all infected devices.
The U.S. Department of Justice (DOJ), the Federal Bureau of Investigation (FBI), and the Defense Criminal Investigative Service (DCIS) carried out seizures of Sality-related domains inside the United States. In Europe, law enforcement agencies seized additional domains hosted there as part of actions carried out by authorities in Bulgaria, Hungary, and Romania.
How Was the Network Disrupted?
The operation relied on sinkhole technology, which redirected the botnet’s communications to infrastructure under the control of the parties conducting the operation. Through its Counter Adversary Operations team, and in cooperation with law enforcement agencies and industry partners, CrowdStrike targeted the so-called super peers—the nodes that serve as the backbone of communications in Sality’s peer-to-peer (P2P) network.
This action made it possible to prevent the distribution of file packages that directly deliver the malicious payload, as well as URL packages containing instructions for downloading it. It also included purging the peer lists on infected devices, with the aim of cutting off their ability to discover new nodes and return to the previous control channels.
From Credential Theft to Cryptocurrency Address Replacement
Sality first appeared, according to the article, in 2003, and has infected more than 15,000 devices since then. Throughout its history, the network has been used to distribute multiple malware families, including credential stealers, spam distribution, proxy services, network exploitation, and distributed denial-of-service (DDoS) attacks.
As for the two separate networks that remained active when the operation was carried out this week, they were used primarily to distribute the EggJagger payload in clipjacking attacks. This tool monitors clipboard contents for cryptocurrency wallet addresses, then silently replaces them with addresses controlled by the operator, potentially turning a payment in which the user copies the address from the clipboard into a transfer to the wrong party.
Why Does This Matter?
The importance of the operation lies in targeting the decentralized infrastructure of a P2P botnet, rather than merely shutting down a single centralized control server. Sality’s persistence for more than 20 years also shows that some malicious networks can change their payloads and functions while maintaining their operational infrastructure. At the same time, the article does not provide a figure for the number of devices actually cleaned, nor does it clarify whether backups of the infrastructure or recovery mechanisms exist that the operator could use in the future.
The operation comes as part of a series of international moves against digital criminal infrastructure since the beginning of the year, including the disruption of the SocksEscort network, the takedown of the control infrastructure for the Aisuru, KimWolf, JackSkid, and Mossad botnets, the taking offline in May of a botnet comprising 17 million devices, and the disruption of the QScan and QTRouter platforms linked to Chinese cyberespionage operations, according to the source.