Sality Is Down. The 15,000 Infected Machines Aren't.
A 23-year-old botnet just got killed — and the killer wasn't a server seizure or a takedown order. Sality, a peer-to-peer malware network that started in 2003 as a classic file-infecting virus (the kind that latched onto executables and spread over network shares, USB drives, and file-sharing networks), has been infecting 15,000+ machines for two decades. International law enforcement, CrowdStrike's Counter Adversary Operations team, and the Shadowserver Foundation just cut its operator off from the entire fleet — by poisoning the one thing every Sality bot trusts: its own peer list. Every Sality bot keeps a list of "super peers," publicly reachable infected machines that form the P2P backbone, and it refreshes that list every 40 minutes. The operation exploited exactly that habit: researchers invalidated the legitimate super peers, swapped in defender-controlled sinkholes, and waited for infected machines to come online on their normal maintenance cycles so the remaining legitimate peers could be purged. The bots are now unreachable for new commands or payloads. The design pattern that got called resilient for years — P2P, no central server to seize — had a maintenance schedule, and it turned out to be exploitable.
The economics of the whole enterprise are almost boring, which is part of what made it work. For the past eight years, Sality's main payload has been EggJagger, a clipboard hijacker: it watches for anything that looks like a cryptocurrency wallet address copied to the clipboard and silently swaps it for an address the operator controls — no prompt, no warning. Copy a Bitcoin or Ethereum address to make a payment, and the funds quietly go somewhere else. CrowdStrike estimates the operator made at least $150,000 that way over the run, and the botnet also powered a handful of DDoS campaigns, including one against a Ukrainian web forum on February 25, 2022 — a day after Russia's invasion began — and one against a Russian crypto exchange that looked like a personal grudge over a transaction. One operator, quietly running one network for 23 years. The quietness was the product.
Here's the part worth sitting with, though: a takedown that severs the control channel doesn't clean anything. Most of Sality's 15,000 hosts sit behind NATs and firewalls where they can't be touched from the outside, and they're now orphaned — infected, dormant, peer lists purged, with no command channel to wake them up. The malware is still on the disk. It'll stay there until the operator comes back, probably the same operator, rebuilding on fresh super peers. That's the uncomfortable tradeoff in sinkhole operations like this one: you win the network war and lose the endpoint war, and the infected machines become a long shelf of landmines. If your environment involves copying crypto addresses by hand — exchanges, treasuries,

Sources
- CrowdStrike: Inside the Sality Botnet Disruption Operation
- Help Net Security: Global sinkhole operation ends Sality botnet's 23-year run
- The Register: Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes
- Decrypt: Sality Botnet Dismantled After Eight Years of Stealing Bitcoin and Ethereum
Comments
Post a Comment