International Operation Disrupts Sality P2P Botnet
Sality began operating in 2003 as file-infecting malware and later developed into a decentralized peer-to-peer network. According to the Justice Department, compromised computers could be used for cryptocurrency theft and cyberattacks without their owners' knowledge. CrowdStrike said two incompatible networks, identified as versions 3 and 4, remained active before the operation and were controlled by the same actor.
CrowdStrike said its Counter Adversary Operations team launched a sinkholing operation on August 31 with the Justice Department, FBI, Defense Criminal Investigative Service, Shadowserver Foundation and international partners. Rather than relying on a central command server, Sality bots exchanged instructions directly. The defenders exploited weaknesses in that design by invalidating legitimate super peers in each bot's finite peer list and inserting controlled sinkhole entries.
Each infected machine checked its stored peers about every 40 minutes, raising the reputation of responsive systems and eventually removing unreachable ones, CrowdStrike reported. Manipulating that process progressively isolated bots from the operator and prevented new URL packs or direct payload files from propagating. Authorities also took down URLs hosting current payloads so machines carrying earlier instructions could not retrieve additional malware during the transition.
Sality spread by attaching polymorphic code to executable files and moving through network shares, removable drives and file sharing. CrowdStrike said the botnet delivered malware used for credential theft, spam, proxy services, network exploitation and distributed denial-of-service attacks. Its EggJagger cryptocurrency-stealing payload monitored clipboards for wallet addresses and replaced them with attacker-controlled addresses; CrowdStrike estimated that technique stole at least 12.1 million rubles, approximately $150,000.
The Shadowserver Foundation is working with internet service providers and computer security incident response teams to identify infected systems, notify victims and support remediation, the Justice Department said. The disruption blocks new operator tasking but does not remove Sality from compromised files, so administrators should use current endpoint protection, inspect systems for infection and restore affected executables from trusted sources. Reuters reported that the coordinated action targeted an operation that had persisted for more than two decades.