Key facts
- A 20-year-old Russian cybercrime operation named "Sality" is being dismantled.
- U.S. law enforcement seized domains used by the hackers for spam, DDoS attacks, and cryptocurrency theft.
- Cybersecurity firm CrowdStrike disrupted the botnet's network, cutting it off from its controller.
- The operation was a coordinated effort between U.S. and European law enforcement agencies.
- Sality's peer-to-peer architecture made it resilient, but CrowdStrike exploited this to disable it.
A long-running Russian cybercrime operation, known as "Sality" and active for two decades, is being dismantled through a coordinated effort by U.S. law enforcement and cybersecurity firm CrowdStrike.
U.S. officials announced Tuesday that they had seized web domains utilized by the hackers for activities such as sending spam, conducting distributed denial-of-service attacks, and stealing cryptocurrency. Concurrently, CrowdStrike confirmed it had severed the botnet's connection to its controller, effectively disabling its command and control infrastructure.
The takedown was publicly demonstrated by CrowdStrike at its Day Zero threat intelligence summit in Las Vegas on Monday. The FBI and the U.S. Justice Department stated that the operation was a result of collaboration with European law enforcement and other international partners.
First Assistant United States Attorney Bill Essayli emphasized the significant threat posed by cybercriminals and botnets to national security and the economy. Despite being overshadowed in recent years by more disruptive ransomware operations, Sality, first identified in 2003, represented one of the internet's most enduring cybercriminal enterprises.
CrowdStrike explained that Sality's peer-to-peer architecture, which made it resilient by allowing commands through a distributed network of compromised machines, was turned against it. By seeding the network with false information, CrowdStrike tricked the botnet's components into disconnecting from their central controller. CrowdStrike researcher Tillmann Werner described the effort as the most complex botnet takeover they had ever undertaken, highlighting the botnet's design for resilience.
David Watson, director of The Shadowserver Foundation, which also participated in the takedown, characterized Sality as "old-school" but still dangerous. The next phase involves observing whether Sality's unidentified creator attempts to regain control or rebuild the botnet.
