All NewsEducationTVBrokers
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
All NewsHome
← Back to US Politics & Policy

US officials and CrowdStrike dismantle two-decade-old Russian cybercrime operation

Created at 1 Sep · 10:07 PM1 source↑ Market-relevant
IN SHORT

U.S. law enforcement and cybersecurity firm CrowdStrike announced the dismantling of a 20-year-old Russian hacking operation known as "Sality." Officials seized domains used by the hackers, while CrowdStrike disrupted the botnet's command network.

Key Numbers

2003year Sality was first spotted
two decadesduration of Sality operation

Who's Involved

Sality
two-decade-old Russian hacking operation
U.S. law enforcement officials
announced the dismantling of the operation
CrowdStrike
cybersecurity company involved in the takedown
Bill Essayli
First Assistant United States Attorney
Tillmann Werner
CrowdStrike researcher
David Watson
Director of The Shadowserver Foundation
US officials and CrowdStrike dismantle two-decade-old Russian cybercrime operation

↳ Why This Matters

The dismantling of the Sality botnet, one of the longest-running cybercrime operations, represents a significant blow to organized cybercriminal activity and enhances global cybersecurity by removing a persistent threat to national security and economies.

Key facts

  • A 20-year-old Russian cybercrime operation named "Sality" is being dismantled.
  • U.S. law enforcement seized domains used by the hackers for spam, DDoS attacks, and cryptocurrency theft.
  • Cybersecurity firm CrowdStrike disrupted the botnet's network, cutting it off from its controller.
  • The operation was a coordinated effort between U.S. and European law enforcement agencies.
  • Sality's peer-to-peer architecture made it resilient, but CrowdStrike exploited this to disable it.

A long-running Russian cybercrime operation, known as "Sality" and active for two decades, is being dismantled through a coordinated effort by U.S. law enforcement and cybersecurity firm CrowdStrike.

U.S. officials announced Tuesday that they had seized web domains utilized by the hackers for activities such as sending spam, conducting distributed denial-of-service attacks, and stealing cryptocurrency. Concurrently, CrowdStrike confirmed it had severed the botnet's connection to its controller, effectively disabling its command and control infrastructure.

The takedown was publicly demonstrated by CrowdStrike at its Day Zero threat intelligence summit in Las Vegas on Monday. The FBI and the U.S. Justice Department stated that the operation was a result of collaboration with European law enforcement and other international partners.

First Assistant United States Attorney Bill Essayli emphasized the significant threat posed by cybercriminals and botnets to national security and the economy. Despite being overshadowed in recent years by more disruptive ransomware operations, Sality, first identified in 2003, represented one of the internet's most enduring cybercriminal enterprises.

CrowdStrike explained that Sality's peer-to-peer architecture, which made it resilient by allowing commands through a distributed network of compromised machines, was turned against it. By seeding the network with false information, CrowdStrike tricked the botnet's components into disconnecting from their central controller. CrowdStrike researcher Tillmann Werner described the effort as the most complex botnet takeover they had ever undertaken, highlighting the botnet's design for resilience.

David Watson, director of The Shadowserver Foundation, which also participated in the takedown, characterized Sality as "old-school" but still dangerous. The next phase involves observing whether Sality's unidentified creator attempts to regain control or rebuild the botnet.

Frequently asked questions

Sality is a Russian cybercrime operation and botnet that has been active for approximately two decades, first spotted in 2003. It was used for activities like sending spam, conducting DDoS attacks, and stealing cryptocurrency.

The takedown involved U.S. law enforcement agencies, including the FBI and the U.S. Justice Department, in coordination with European law enforcement and the cybersecurity firm CrowdStrike. The Shadowserver Foundation also participated.

U.S. officials seized the web domains used by the hackers. CrowdStrike disrupted the botnet by seeding its peer-to-peer network with bogus information, tricking compromised machines into disconnecting from their controller.

No, the creator of the Sality botnet has not yet been publicly identified.

What Happens Next

01Observe if Sality's creator attempts to regain control or re-create the botnet.

How It Developed

A two-decade-old Russian hacking operation dubbed "Sality" is being dismantled.
U.S. law enforcement seized web domains used by the hackers.
CrowdStrike cut off a network of compromised computers from the operation's mastermind.
The operation was dismantled at CrowdStrike's Day Zero threat intelligence summit.
The FBI and U.S. Justice Department coordinated with European law enforcement.
The botnet's peer-to-peer architecture made it resistant to takedowns.
CrowdStrike used bogus information to trick botnet components into disconnecting.
The creator of Sality has yet to be publicly identified.

Sources

T1
Russian cybercrime operation being dismantled after two decades, US officials and CrowdStrike sayReuters

Related Stories

Homeland Security to Expand Voter Fraud Investigations
1 Sep · 1:19 PM
US university to pay $2.1 million over undisclosed China ties
1 Sep · 1:21 AM
US Congress probes foreign countries behind scam calls
1 Sep · 10:36 PM
Oracle licensing practices under EU antitrust scrutiny, source says
1 Sep · 8:37 PM
US Treasury Secretary: Russia economic cooperation impossible until Ukraine war ends
1 Sep · 2:16 PM