Urgent.News

What's breaking now, across thousands of outlets.

Tech

Russian cybercrime operation being dismantled after two decades: U.S. and CrowdStrike

Though it has been overshadowed by more disruptive cybercriminals, the Russian hacking operation remains one of the internet's longest-running cybercriminal enterprises.

Russian cybercrime operation being dismantled after two decades: U.S. and CrowdStrike

In a significant operation, U.S. law enforcement and cybersecurity firm CrowdStrike have dismantled a two-decade-old Russian hacking group known as "Sality." The joint effort resulted in the seizure of web domains utilized by the hackers to carry out spam campaigns, distributed denial-of-service attacks, and cryptocurrency thefts. CrowdStrike also severed a network of compromised computers that were under the control of the botnet's mastermind.

The dismantling of Sality took place on Monday during a live event at CrowdStrike's Day Zero threat intelligence summit in Las Vegas. The FBI and U.S. Justice Department confirmed the operation was carried out in coordination with European law enforcement and other organizations, emphasizing the ongoing threat posed by cybercriminals, botnets, and malware to national security and the economy.

Although Sality has been overshadowed by more aggressive ransomware groups in recent years, it remains one of the internet's longest-running cybercriminal enterprises. First spotted in 2003, the operation was based in Russia, though the Russian Embassy in Washington did not provide further details.

Sality's peer-to-peer architecture made it particularly resilient to law enforcement efforts, as it could receive commands through a diffuse network of compromised machines. However, CrowdStrike managed to exploit this very strength by flooding the network with false information, causing the botnet components to disconnect from their creator.

CrowdStrike researcher Tillmann Werner highlighted the complexity of the operation, stating that it was the most challenging botnet takeover they had ever undertaken. The painstaking process involved reverse-engineering the botnet's structure, identifying weak points, and building the necessary infrastructure to dismantle it.

David Watson, director of the nonprofit security group The Shadowserver Foundation, which also participated in the takedown, noted that while Sality is "quite old-school," it still poses a significant threat. Watson emphasized the need to observe the actions of the botnet's creator, who has yet to be publicly identified, to determine if they will attempt to regain control or recreate the botnet.

Written by urgent.news from Japan Times's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at japantimes.co.jp →

More in Tech

How 'Shōshō' Became 'Shomo' — Permission Character List Was Trimming Japanese

📝 Originally published (in Japanese) at forge.workstyle.tech . I received a report about the avatar for the inquiry desk: "しょうしょうおまちください" becomes "しょもおまちください".

  • Original Japanese query corrupted during TTS process
  • Missing character 々 caused "しょうしょう" to become "しょも"
  • Seven other missing characters affected audio synthesis

More from Wednesday 2 September →