A coordinated international operation has dismantled key infrastructure used by Sality, disrupting a peer-to-peer botnet that has remained active for more than 20 years.

 

 

Authorities in the United States and Europe worked alongside private cybersecurity companies to seize domains and interfere with the communication system that allowed Sality operators to control infected computers. The operation involved the US Department of Justice, FBI and Defense Criminal Investigative Service, with support from Europol and Eurojust. Authorities in Bulgaria, Hungary and Romania also seized Sality-linked domains hosted in Europe.

CrowdStrike participated in the operation by targeting the peer-to-peer infrastructure connecting infected devices. Instead of depending entirely on traditional centralized command-and-control servers, Sality used infected machines to communicate with other members of the botnet, making its infrastructure more difficult to disable through conventional server seizures.

Investigators and researchers disrupted this network using a sinkhole operation targeting Sality’s known “super peers,” which acted as important communication points between infected systems. The intervention prevented malware files and instructions for downloading additional payloads from continuing to spread through the network.

CrowdStrike says the operation has left the remaining Sality botnet infrastructure outside the control of its operators.

Sality first appeared in 2003 and developed into a long-running malware operation capable of using infected Windows computers for multiple forms of cybercrime. More than 15,000 devices have been infected with malware through the operation since its emergence.

CrowdStrike attributes Sality to a cybercriminal group it tracks as SALTY SPIDER, which researchers believe is likely operating from the Republic of Bashkortostan in Russia. The attribution comes from the security company rather than law enforcement authorities.

Over its long history, Sality has been associated with malware used for credential theft, spam campaigns, proxy services, exploitation of networks and distributed denial-of-service attacks.

More recently, however, the botnet’s purpose had become increasingly focused on cryptocurrency theft.

Two Sality networks that remained operational before the takedown were primarily being used to distribute EggJagger. The malware performs a technique known as clipjacking, monitoring the clipboard of an infected computer for cryptocurrency wallet addresses.

When a victim copies a wallet address before making a transaction, EggJagger can silently replace it with an address controlled by the attackers. A user who fails to notice the substitution may then send cryptocurrency directly to the criminals instead of the intended recipient.

CrowdStrike says EggJagger had been Sality’s primary malware payload for approximately eight years.

The international operation targeted both the domains supporting Sality and the peer-to-peer architecture that allowed infected computers to receive new instructions and malware. By redirecting critical communication points and removing peer information from infected systems, investigators were able to isolate machines from the criminal network.

After operating continuously for more than two decades, Sality is now no longer under the control of its operators, according to CrowdStrike.

Leave a Reply