International operation disrupts 23-year Sality P2P botnet

Law enforcement in the US, Bulgaria, Hungary and Romania, with CrowdStrike, isolated Sality-infected machines and redirected them to CrowdStrike-operated sinkholes.
An international law enforcement operation working with cybersecurity firm CrowdStrike disrupted the Sality peer-to-peer botnet that was first observed in 2003. Authorities in the United States, Bulgaria, Hungary and Romania coordinated to isolate infected machines and redirect their traffic to sinkholes operated by CrowdStrike.
Sality spread by attaching itself to executable files and removable media rather than using a central command server. The botnet relied on a peer-to-peer design with super peers — infected machines that formed the network backbone — and a simple reputation system that removed peers that were frequently offline.
CrowdStrike manipulated the protocol that managed super peer lists, removing legitimate super peers and inserting sinkholes so infected hosts would update their lists and connect to defender-controlled nodes. Law enforcement also removed URLs that delivered Sality installers and related payloads to prevent infected machines from fetching new components.
Security researchers say Sality was used to deliver information stealers, proxy services and distributed denial-of-service tools. For about eight years it primarily served EggJagger, a clipjacking tool estimated to have stolen at least $150,000 in Bitcoin and Ethereum.
CrowdStrike reported: “The criminal behind Sality has lost the ability to communicate with infected machines. The disruption operation isolates all peers in the network from their control. All Sality-infected machines now beacon to CrowdStrike-operated sinkholes.”
The Shadowserver Foundation is working with internet service providers and national computer security incident response teams to identify infected systems and notify owners so they can remove the malware. Security teams say thorough cleanup and software updates are required to eliminate remaining risk.








