news.mlab.sh
Back to the feed
threat-intel

23-Year-Old Sality P2P Botnet Disrupted

Medium
Summary

After nearly two decades, the Sality P2P botnet has been successfully dismantled through a coordinated international law enforcement operation. The botnet, known for distributing various malware and facilitating clipjacking, relied on a flawed trust mechanism, allowing law enforcement to isolate infected machines and prevent further payload distribution. This disruption significantly reduces the threat posed by Sality and its associated malware.

The Sality P2P botnet, initially detected in 2003, has been shut down after 23 years of operation. For a significant portion of its lifespan, Sality was primarily utilized to distribute various malware, including information stealers and proxy services, and to facilitate the EggJagger clipjacking tool, which is believed to have generated substantial revenue through stolen cryptocurrency. The botnet’s longevity stemmed from its unique architecture, which avoided reliance on a central command-and-control (C&C) server and instead operated on a peer-to-peer network. This design allowed Sality to spread through file infectors, attaching itself to executables on disk and removable media, making it difficult to eradicate.

However, the very characteristic that enabled Sality’s persistence – its blind trust of peers without authentication – ultimately led to its downfall. The botnet periodically checked the availability of its super peers (infected machines forming the backbone of the P2P network), and if a peer was online, it built reputation, while offline peers were purged. CrowdStrike exploited this behavior by performing protocol-level manipulation, removing super peer entries and injecting sinkholes into the list, effectively isolating infected machines and preventing them from receiving new payloads.

Law enforcement agencies in the US, Bulgaria, Hungary, and Romania collaborated with CrowdStrike to coordinate the disruption. These agencies took down the URLs hosting Sality payloads, ensuring that infected machines could no longer receive new malware. The Shadowserver Foundation is also working with ISPs and CSIRTs to identify and remediate Sality infections. This operation represents a significant win for cybersecurity and a reduction in the threat landscape.

Read the full article at SecurityWeek