Key facts
- A two-decade-old Russian hacking operation known as Sality has been dismantled.
- U.S. law enforcement seized web domains used by the hackers.
- Cybersecurity firm CrowdStrike cut off the compromised computer network from its controller.
- The operation was coordinated with European law enforcement.
- Sality's peer-to-peer architecture made it resistant to previous takedown attempts.
A two-decade-old Russian hacking operation, known as Sality, is being dismantled through a coordinated effort by U.S. law enforcement and cybersecurity firm CrowdStrike. U.S. officials announced the seizure of web domains utilized by the hackers for illicit activities such as sending spam, conducting distributed denial-of-service attacks, and stealing cryptocurrency. Simultaneously, CrowdStrike confirmed it had severed the botnet's network of compromised computers from its controller.
The operation was revealed on Tuesday, following a live dismantling demonstration by CrowdStrike at its Day Zero threat intelligence summit in Las Vegas on Monday. The FBI and U.S. Justice Department stated that the takedown was executed in collaboration with European law enforcement agencies and other organizations.
First Assistant United States Attorney Bill Essayli emphasized the significant threat posed by cybercriminals and botnets to national security and the economy. Sality, first identified in 2003, has been one of the internet's most enduring cybercriminal enterprises, despite being overshadowed in recent years by more disruptive ransomware groups. The Justice Department indicated the operation was based in Russia.
Sality's peer-to-peer architecture had previously made it resilient to law enforcement actions. However, CrowdStrike exploited this by feeding the network false information, causing its components to disconnect from the mastermind. CrowdStrike researcher Tillmann Werner described the effort as the most complex botnet takeover they have ever conducted, highlighting the botnet's design for survival.
David Watson of The Shadowserver Foundation, also involved in the takedown, noted that while Sality is an older threat, it remains dangerous. The next phase will involve observing the actions of Sality's creator, who has not yet been publicly identified, to see if they attempt to regain control or rebuild the botnet.
