All NewsEducationTVBrokers
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
All NewsHome
← Back to AI & Technology

US and CrowdStrike dismantle 20-year-old Russian Sality cybercrime operation

Created at 3 Sep · 1:06 AM1 source↑ Market-relevant
IN SHORT

U.S. law enforcement and cybersecurity firm CrowdStrike announced the dismantling of the Sality botnet, a Russian hacking operation active for two decades. Officials seized domains used by the hackers, while CrowdStrike severed the compromised computer network from its controller.

Key Numbers

2003year Sality first spotted
two decadesduration of Sality operation

Who's Involved

Sality
two-decade-old Russian hacking operation
U.S. law enforcement officials
announced dismantling of Sality operation
CrowdStrike
cybersecurity company involved in takedown
Bill Essayli
First Assistant United States Attorney
Tillmann Werner
CrowdStrike researcher
David Watson
Director of The Shadowserver Foundation
US and CrowdStrike dismantle 20-year-old Russian Sality cybercrime operation

↳ Why This Matters

The dismantling of the Sality botnet marks a significant success in combating long-standing cybercrime, potentially disrupting a major source of spam, DDoS attacks, and cryptocurrency theft that has operated for two decades.

Key facts

  • A two-decade-old Russian hacking operation known as Sality has been dismantled.
  • U.S. law enforcement seized web domains used by the hackers.
  • Cybersecurity firm CrowdStrike cut off the compromised computer network from its controller.
  • The operation was coordinated with European law enforcement.
  • Sality's peer-to-peer architecture made it resistant to previous takedown attempts.

A two-decade-old Russian hacking operation, known as Sality, is being dismantled through a coordinated effort by U.S. law enforcement and cybersecurity firm CrowdStrike. U.S. officials announced the seizure of web domains utilized by the hackers for illicit activities such as sending spam, conducting distributed denial-of-service attacks, and stealing cryptocurrency. Simultaneously, CrowdStrike confirmed it had severed the botnet's network of compromised computers from its controller.

The operation was revealed on Tuesday, following a live dismantling demonstration by CrowdStrike at its Day Zero threat intelligence summit in Las Vegas on Monday. The FBI and U.S. Justice Department stated that the takedown was executed in collaboration with European law enforcement agencies and other organizations.

First Assistant United States Attorney Bill Essayli emphasized the significant threat posed by cybercriminals and botnets to national security and the economy. Sality, first identified in 2003, has been one of the internet's most enduring cybercriminal enterprises, despite being overshadowed in recent years by more disruptive ransomware groups. The Justice Department indicated the operation was based in Russia.

Sality's peer-to-peer architecture had previously made it resilient to law enforcement actions. However, CrowdStrike exploited this by feeding the network false information, causing its components to disconnect from the mastermind. CrowdStrike researcher Tillmann Werner described the effort as the most complex botnet takeover they have ever conducted, highlighting the botnet's design for survival.

David Watson of The Shadowserver Foundation, also involved in the takedown, noted that while Sality is an older threat, it remains dangerous. The next phase will involve observing the actions of Sality's creator, who has not yet been publicly identified, to see if they attempt to regain control or rebuild the botnet.

Frequently asked questions

Sality is a two-decade-old Russian hacking operation and botnet that has been used for activities such as sending spam, carrying out distributed denial-of-service attacks, and stealing cryptocurrency.

The dismantling involved U.S. law enforcement officials, cybersecurity company CrowdStrike, and coordinated efforts with European law enforcement and other organizations.

Sality utilized a peer-to-peer architecture that made it highly resistant to law enforcement actions, allowing it to receive commands through a diffuse network of compromised machines.

CrowdStrike reversed the botnet's strength against it by seeding the network with bogus information, tricking its components into disconnecting from their creator.

What Happens Next

01Monitor the actions of Sality's creator to see if they attempt to regain control or rebuild the botnet.

How It Developed

U.S. law enforcement and CrowdStrike announced the dismantling of the Sality hacking operation.
The operation, active for two decades, was dismantled by U.S. officials and CrowdStrike.
U.S. officials seized web domains used by the hackers.
CrowdStrike cut off a network of compromised computers from the botnet's mastermind.
The takedown was coordinated with European law enforcement and other organizations.
CrowdStrike researcher Tillmann Werner described the botnet takeover as the most complex they have ever undertaken.

Sources

T1
Russian cybercrime operation being dismantled after two decades, US officials and CrowdStrike sayPiQSuite
T2
Russian cybercrime operation being dismantled after two decades, US ...globalbankingandfinance.com

Related Stories

OpenAI developing automated AI shutdown tools after agent 'went rogue'
2 Sep · 8:05 PM
Hackers Suspected of Breaching Major ID Verification Service
2 Sep · 7:46 PM
FBI Probes Dark Web Sale of 153 Million Driver's Licenses
2 Sep · 8:36 PM
Russia's Starlink rival Rassvet faces launch setbacks
2 Sep · 11:26 AM
China targets AI deepfakes and clickbait on social media platforms
2 Sep · 9:20 AM