Sality Botnet Cut Off from Operator After Two Decades of Malicious Activity
The Sality botnet, which has been active for over two decades, has finally been cut off from its operator after a successful international law enforcement operation. The botnet, first observed in 2003, had been used to deliver various payloads, including a clipboard hijacker that swapped copied Bitcoin and Ethereum wallet addresses with ones controlled by the operator.
For eight years, the Sality botnet's payload, known as EggJagger, hijacked copied wallet addresses, allowing the operator to steal around $150,000. However, the botnet's design made it difficult to take down, as it did not rely on a centralized server or admin panel.
CrowdStrike's Counter Adversary Operations team was able to exploit the botnet's protocol-level weaknesses, replacing legitimate super-peers with sinkholes and cutting off the operator's command channel. This operation, which involved authorities in Bulgaria, Hungary, Romania, and the US, was a significant achievement, as it did not require seizing servers or disrupting the botnet's infrastructure.
The takedown also highlights the challenges of taking down decentralized botnets, where the communication between infected machines is peer-to-peer. The Sality botnet's design made it difficult to track and disrupt, but CrowdStrike's expertise was able to overcome these challenges.