Sality, one of the longest-running botnets, finally gets disrupted
Authorities in the U.S., Bulgaria, Hungary, and Romania successfully disrupted Sality, one of the internet’s longest-running botnets, after a complex operation targeting the malware’s decentralized peer-to-peer network. The disruption, involving a ‘sinkhole’ operation, severed connections between over 15,000 infected computers, effectively dismantling the botnet. While the operator remains unidentified, the action highlights international cooperation in combating persistent cyber threats.
U.S. and European authorities announced the disruption of Sality, one of the internet’s longest-running botnets, after a coordinated operation targeting the malware’s unique peer-to-peer architecture. The operation involved collaboration between authorities in the U.S., Bulgaria, Hungary, and Romania, alongside cybersecurity company CrowdStrike and the nonprofit Shadowserver Foundation.
Sality began in 2003 as a virus that infected executable files, spreading when compromised files were copied between computers. Over time, it evolved into a decentralized botnet capable of distributing malware used for various malicious activities, including credential theft, spam, proxy services, and denial-of-service attacks. For roughly the past eight years, CrowdStrike reported that Sality primarily distributed EggJagger, malware designed to monitor a computer’s clipboard for cryptocurrency wallet addresses. When a wallet address is detected, EggJagger can replace it with one controlled by the attacker, redirecting a payment if the victim does not notice the substitution before completing the transaction. CrowdStrike estimates the operator stole at least $150,000 in cryptocurrency through this technique.
Unlike traditional botnets relying on a central command-and-control server, Sality operated on a decentralized network where infected computers communicated directly with one another. This design made it difficult to disrupt using conventional sinkholing techniques. CrowdStrike researchers targeted the ‘super peer’ lists – lists of publicly reachable systems used to maintain the decentralized network – by injecting false information, causing infected machines to lose contact with other members and ultimately, its operator.
Authorities seized Sality-linked domains in the U.S. and additional domains in Europe that infected systems could otherwise have used to retrieve new payloads. Shadowserver is working with internet service providers and national computer-security response teams to identify the more than 15,000 infected systems still connected to Sality when it was disrupted and to alert their owners.
U.S. officials presented the action as an example of cooperation between law enforcement and the cybersecurity industry, linking it to the Trump administration’s cyber strategy, whose first pillar calls for the U.S. to shape adversary behavior. The operator of Sality remains publicly unidentified and at large, and it is unclear whether the disruption will prevent them from attempting to rebuild the botnet or develop replacement infrastructure.
