In a coordinated effort announced Tuesday, U.S. law‑enforcement agencies and the cybersecurity company CrowdStrike reported the dismantling of the Russian‑originated Sality botnet, one of the longest‑running cybercrime operations on the internet.
National and international cooperation
The FBI and the U.S. Department of Justice said the operation was carried out alongside European law‑enforcement partners and other organizations. The effort focused on seizing the web domains the hackers used to commandeer computers for spam, distributed denial‑of‑service attacks and cryptocurrency theft.
CrowdStrike’s technical strike
At CrowdStrike’s Day Zero threat‑intelligence summit in Las Vegas, the company demonstrated how it cut off the botnet’s network of compromised machines from its hidden controller. By injecting bogus data into Sality’s peer‑to‑peer architecture, the firm forced the botnet’s components to disconnect from the mastermind.
“This was the most complex botnet takeover we have ever done,” said CrowdStrike researcher Tillmann Werner. “It was built to be resilient and to survive takedown or takeover, which is why it has persisted for so long.”
Impact and next steps
David Watson, director of the nonprofit security group The Shadowserver Foundation, noted that despite its age, Sality remains a “vector into a lot of organizations.” He said the next phase will involve monitoring whether the unidentified creator attempts to rebuild or regain control of the network.
“What does he do? Does he fight back?” Watson asked.
The Justice Department confirmed the operation was based out of Russia but provided no further details. The Russian Embassy in Washington did not immediately respond to a request for comment.
Original reporting: Appleton, WI News Feed (HLL/CB) — read the source article.