Urgent.News

What's breaking now, across thousands of outlets.

Tech

Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes

23-year-old botnet down

Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes

On Monday, international law enforcement agencies, in collaboration with CrowdStrike and Shadowserver Foundation, successfully dismantled the Sality botnet, a 23-year-old peer-to-peer network that infected over 15,000 computers worldwide. The botnet, active since 2003, was responsible for a wide range of malicious activities, including stealing credentials, spreading spam, providing proxy services, exploiting networks, and executing distributed denial-of-service (DDoS) attacks.

For the past eight years, Sality primarily delivered EggJagger, a tool that monitored user clipboards for cryptocurrency wallet addresses, then covertly replaced them with addresses controlled by the attackers. When a victim copied a Bitcoin or Ethereum address for a payment, the malware rerouted the funds to the criminals' accounts, with CrowdStrike estimating that the botnet's operators had stolen at least $150,000 in cryptocurrency using EggJagger alone.

CrowdStrike's Counter Adversary Operations team, working alongside international law enforcement and industry partners, executed a peer-to-peer sinkhole operation to disrupt Sality. This operation isolated infected machines, severing the criminals' ability to communicate with devices on their network. As a result, the bots could no longer receive instructions for payload downloads or transfers, effectively dismantling the botnet.

The technical writeup from CrowdStrike's Counter Adversary Operations team explained that the operation targeted the core data structure of each bot's network awareness: its peer list. Every 40 minutes, the bots checked their peers to see if they were still online. Peers that failed to respond were removed from the network. The counterattack took advantage of this process by removing legitimate super peers from each bot's peer list, continually isolating more infected machines, and inserting purposely-built sinkhole entries into the peer lists.

This approach provided police and cyber operatives with visibility into the operation's progress and facilitated the notification of victims. Furthermore, the US Justice Department, FBI, and Department of Defense Office of Inspector General's Defense Criminal Investigative Service seized Sality-linked domains in the United States, while international law enforcement in Bulgaria, Hungary, and Romania took action against additional Sality-linked domains hosted in Europe.

The Shadowserver Foundation is currently working with internet service providers and Computer Security Incident Response Teams (CSIRTs) to identify infections and assist in victim notification and remediation.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at theregister.com →

More in Tech

EKS vs ECS vs Fargate: Choosing AWS Container Compute

"Should we use EKS?" is one of the most over-answered-with-yes questions in AWS. Kubernetes is powerful, but it's not free, in money or operational effort.

  • ECS is AWS's own container orchestrator, simpler and deeply integrated with low control-plane cost
  • EKS provides Kubernetes ecosystem access for portability and expertise requirements
  • Fargate is serverless compute mode eliminating node management, best for variable workloads

async/await without the pitfalls

async/await without the pitfalls Async/await is the bread and butter of modern JavaScript. It makes asynchronous code look synchronous, which is great for readability.

More from Tuesday 1 September →