03.09.2026 07:00

Share with others:

Share

How was the Sality botnet shut down after two decades?

Photo: Pixabay
Photo: Pixabay

In a major international law enforcement operation, the Sality hacking network, one of the world’s oldest and most persistent peer-to-peer (P2P) botnets, has finally been taken down after nearly a quarter of a century. First spotted by experts in 2003, the malicious system has been used to spread various forms of malware over the years, including data-stealing tools, proxy services, and software to carry out denial-of-service attacks.

Over the past eight years, the network has been primarily used to spread the EggJagger tool, a specialized clipboard replacement code that is estimated to have netted attackers at least €132,800 in bitcoin and ethereum cryptocurrencies.

The key to Sality's incredible longevity was its architecture. It spread like a classic file infector, attaching itself to executable files on hard drives and removable media. Because it did not rely on a single central command server to update its code, it was extremely difficult to completely disable.

Ironically, the very protocol that had enabled the network to survive for more than 20 years also became its greatest weakness. The network blindly trusted all connected computers without verifying their identities or requiring any authentication. Infected devices, or bots, regularly checked the reachability of other devices on their list of so-called superlinks that formed the backbone of the P2P network. Computers that were reachable gradually gained trust, while those that were unreachable were eventually removed from the list.

This specific behavior was exploited by experts from CrowdStrike. Using protocol-level manipulation, they gradually removed legitimate superlink entries from the lists, isolating infected computers. At the same time, they redirected traffic in the system to their own fake servers, or sinkhole servers.

In a coordinated effort with law enforcement agencies in the United States, Bulgaria, Hungary, and Romania, they then seized and removed the websites hosting the malicious files, preventing the infected devices from receiving any further updates. This effectively prevented the criminals operating the Sality network from communicating with the infected computers, as the devices were now redirected to CrowdStrike’s secure infrastructure.

As part of the operation, The Shadowserver Foundation is working with Internet service providers and national Cybersecurity Response Teams (CSIRTs) to identify all victims and assist in the complete cleanup of their computers.


Interested in more from this topic?
information security cyber security


What are others reading?