Sality P2P botnet disrupted after 23 years in US-led operation

This digest was compiled by AI from multiple sources — links to the originals are below.
The Sality peer-to-peer botnet, active since 2003, has been disrupted in a coordinated international law enforcement operation. CrowdStrike manipulated the botnet's peer list to isolate infected machines, while authorities in the US, Bulgaria, Hungary, and Romania seized payload-hosting URLs. The botnet is believed to have stolen at least $150,000 in cryptocurrency through the EggJagger clipjacking tool.
Key Facts
- Sality was first observed in 2003 and operated for 23 years.
- The botnet primarily distributed the EggJagger clipjacking tool, which stole at least $150,000 in Bitcoin and Ethereum.
- CrowdStrike performed protocol-level manipulation of the peer list to isolate infected machines and inject sinkholes.
- Law enforcement in the US, Bulgaria, Hungary, and Romania took down URLs hosting Sality payloads.
- The Shadowserver Foundation is working with ISPs and CSIRTs to identify victims and clean up infections.
Botnet Architecture
Sality spread through a file infector, attaching itself to executables on disk and removable media. The botnet did not rely on a central command-and-control server for code updates. Sality bots periodically checked the accessibility of peers in their list of super peers, which formed the backbone of the P2P network. Online peers built reputation, while offline peers lost it and were eventually purged.
Disruption Operation
CrowdStrike exploited the botnet's blind trust in peers by removing super peer entries and injecting sinkholes into the list. The criminal behind Sality has lost the ability to communicate with infected machines, according to CrowdStrike. All Sality-infected machines now beacon to CrowdStrike-operated sinkholes. The Shadowserver Foundation is assisting ISPs and CSIRTs in identifying botnet victims.