CrowdStrike and the FBI are breaking down Sality after 23 years.

CrowdStrike and the FBI are breaking down Sality after 23 years.

      Sality has been infecting computers since 2003, which makes it older than the iPhone, Facebook, and much of the current security industry trying to dismantle it. According to Reuters, US law enforcement and CrowdStrike began working on taking it apart this week.

      For over twenty years, the operation has been utilized for fairly typical cybercrime activities. Infected systems have been employed to distribute spam, initiate distributed denial-of-service attacks, and steal cryptocurrency, with criminals switching tactics as different opportunities proved lucrative.

      The method employed by authorities to dismantle it is rather unique. CrowdStrike reverse-engineered the botnet, pinpointed vulnerabilities in its design, and then injected false information that led infected machines to disconnect from their controller. "This was the most complex botnet takeover we have ever executed," remarked Tillmann Werner, a researcher at CrowdStrike. The company revealed details of the operation during its Day Zero threat intelligence summit in Las Vegas.

      Sality's prolonged existence can be attributed in part to its design. It propagated by infecting executable files instead of relying on a single command server, and its peer-to-peer structure meant there was no central machine that could simply be taken offline to disrupt the entire network.

      US authorities managed the legal aspects of the operation. The FBI and Justice Department confiscated the web domains utilized to control the infected machines, thereby eliminating a segment of the infrastructure while CrowdStrike focused on severing the remaining connections. "Cybercriminals, botnets, and malware pose a clear and present danger," commented Bill Essayli, first assistant United States attorney. David Watson from the Shadowserver Foundation characterized Sality as a gateway into numerous organizations.

      This helps clarify why a 23-year-old botnet is still significant to dismantle. Sality's value did not solely stem from its capabilities but from the access it provided to compromised networks, which could then be exploited or sold for additional attacks.

      The problem is not confined to the countries mentioned in the announcement. Old infections remain a threat in Europe as well, where industrial systems, small business servers, and public sector machines may still run software dated enough to be susceptible to malware created in 2003.

      The endurance of an infection reflects as much about the victims as it does about the attackers. Machines can stay compromised for years because no one notices, no one updates them, or the software continues operating on systems that their owners often overlook.

      Operations like this do not necessarily result in arrests, and no such announcements have been made in this situation. When the operators are beyond the reach of the judicial system, seizing infrastructure and severing connections are among the few viable strategies.

      Private security firms taking a more proactive stance is becoming increasingly typical. The US has now permitted private companies to conduct cyber operations overseas, and CrowdStrike’s deployment of false data within a criminal network aligns with the evolving boundary between cybersecurity and offensive operations.

      There is no certainty that the takedown will be permanent. Botnets have been dismantled and reconstructed before, and the computers being disconnected today still harbor the vulnerabilities that allowed Sality to infect them in the first place.

      The use of false-data techniques is particularly noteworthy due to its potential broader applications. A distributed network does not necessarily need to be breached through encryption or brute force if its nodes can be convinced that the controller they rely on is no longer available.

      Neither the count of infected machines nor the financial losses associated with the operation have been made public. After more than two decades, both metrics would provide a clearer picture of the extent of Sality's impact.

      The takedown comes at a time when AI-driven cyber threats are at the forefront of discussions, such as the FSB's alert to G20 finance ministers and OpenAI's reports on what its latest models can detect. Sality serves as a reminder that older issues have not vanished just because newer ones are gaining more focus.

      A botnet does not need to be particularly advanced to survive for 23 years; it merely has to remain unnoticed, which surprisingly remains quite easy.

Other articles

Dropbox reports that 5,000 accounts were compromised via a Lenovo login. Dropbox reports that 5,000 accounts were compromised via a Lenovo login. Attackers created Lenovo IDs using the email addresses of victims and gained access to Dropbox accounts without needing a password. None of the accounts had multi-factor authentication enabled. YouTube TV now allows you to stream ESPN Unlimited directly within the app. YouTube TV now allows you to stream ESPN Unlimited directly within the app. YouTube TV has completely incorporated ESPN Unlimited into its app, eliminating the necessity to switch to a different ESPN app for live sports content. PwC anticipates that worldwide investment in AI infrastructure will hit $31.6 trillion by the year 2050. PwC anticipates that worldwide investment in AI infrastructure will hit $31.6 trillion by the year 2050. According to PwC's modeling, annual capital expenditures for data centers are projected to increase from $800 billion to $1.8 trillion by 2050, with the United States accounting for 48% of this growth, and the demand for chips surpassing construction as the primary driving force. Brussels is inquiring with publishers about the effectiveness of Google's AI opt-out option. Brussels is inquiring with publishers about the effectiveness of Google's AI opt-out option. The Commission distributed a questionnaire to publishers regarding Google's AI search opt-out, with responses expected by 28 August. The replies could determine if the opt-out is adequate. Apple's newly appointed CEO will receive a salary of $3 million along with an equity target of $55 million. Apple's newly appointed CEO will receive a salary of $3 million along with an equity target of $55 million. John Ternus receives a base salary of $3 million, a prorated stock award of $2.5 million, and an award for fiscal 2027 aimed at $55 million, with three-quarters of it linked to shareholder return. Google introduces a Canva substitute that enables users to design posters, flyers, and social media posts using AI. Google introduces a Canva substitute that enables users to design posters, flyers, and social media posts using AI. Google introduced Pics, an AI-driven design tool integrated within Workspace, positioning it as a direct competitor to Canva and Adobe Express.

CrowdStrike and the FBI are breaking down Sality after 23 years.

US law enforcement and CrowdStrike are working to dismantle Sality, a Russian cybercrime group that has been active for 23 years, by injecting it with misleading information.