CrowdStrike and the FBI are breaking down Sality after 23 years.
Sality has been infecting computers since 2003, which makes it older than the iPhone, Facebook, and much of the current security industry trying to dismantle it. According to Reuters, US law enforcement and CrowdStrike began working on taking it apart this week.
For over twenty years, the operation has been utilized for fairly typical cybercrime activities. Infected systems have been employed to distribute spam, initiate distributed denial-of-service attacks, and steal cryptocurrency, with criminals switching tactics as different opportunities proved lucrative.
The method employed by authorities to dismantle it is rather unique. CrowdStrike reverse-engineered the botnet, pinpointed vulnerabilities in its design, and then injected false information that led infected machines to disconnect from their controller. "This was the most complex botnet takeover we have ever executed," remarked Tillmann Werner, a researcher at CrowdStrike. The company revealed details of the operation during its Day Zero threat intelligence summit in Las Vegas.
Sality's prolonged existence can be attributed in part to its design. It propagated by infecting executable files instead of relying on a single command server, and its peer-to-peer structure meant there was no central machine that could simply be taken offline to disrupt the entire network.
US authorities managed the legal aspects of the operation. The FBI and Justice Department confiscated the web domains utilized to control the infected machines, thereby eliminating a segment of the infrastructure while CrowdStrike focused on severing the remaining connections. "Cybercriminals, botnets, and malware pose a clear and present danger," commented Bill Essayli, first assistant United States attorney. David Watson from the Shadowserver Foundation characterized Sality as a gateway into numerous organizations.
This helps clarify why a 23-year-old botnet is still significant to dismantle. Sality's value did not solely stem from its capabilities but from the access it provided to compromised networks, which could then be exploited or sold for additional attacks.
The problem is not confined to the countries mentioned in the announcement. Old infections remain a threat in Europe as well, where industrial systems, small business servers, and public sector machines may still run software dated enough to be susceptible to malware created in 2003.
The endurance of an infection reflects as much about the victims as it does about the attackers. Machines can stay compromised for years because no one notices, no one updates them, or the software continues operating on systems that their owners often overlook.
Operations like this do not necessarily result in arrests, and no such announcements have been made in this situation. When the operators are beyond the reach of the judicial system, seizing infrastructure and severing connections are among the few viable strategies.
Private security firms taking a more proactive stance is becoming increasingly typical. The US has now permitted private companies to conduct cyber operations overseas, and CrowdStrike’s deployment of false data within a criminal network aligns with the evolving boundary between cybersecurity and offensive operations.
There is no certainty that the takedown will be permanent. Botnets have been dismantled and reconstructed before, and the computers being disconnected today still harbor the vulnerabilities that allowed Sality to infect them in the first place.
The use of false-data techniques is particularly noteworthy due to its potential broader applications. A distributed network does not necessarily need to be breached through encryption or brute force if its nodes can be convinced that the controller they rely on is no longer available.
Neither the count of infected machines nor the financial losses associated with the operation have been made public. After more than two decades, both metrics would provide a clearer picture of the extent of Sality's impact.
The takedown comes at a time when AI-driven cyber threats are at the forefront of discussions, such as the FSB's alert to G20 finance ministers and OpenAI's reports on what its latest models can detect. Sality serves as a reminder that older issues have not vanished just because newer ones are gaining more focus.
A botnet does not need to be particularly advanced to survive for 23 years; it merely has to remain unnoticed, which surprisingly remains quite easy.
Other articles
CrowdStrike and the FBI are breaking down Sality after 23 years.
US law enforcement and CrowdStrike are working to dismantle Sality, a Russian cybercrime group that has been active for 23 years, by injecting it with misleading information.
