Sality Is Down. The 15,000 Infected Machines Aren't.

A 23-year-old botnet just got killed — and the killer wasn't a server seizure or a takedown order. Sality, a peer-to-peer malware network that started in 2003 as a classic file-infecting virus (the kind that latched onto executables and spread over network shares, USB drives, and file-sharing networks), has been infecting 15,000+ machines for two decades. International law enforcement, CrowdStrike's Counter Adversary Operations team, and the Shadowserver Foundation just cut its operator off from the entire fleet — by poisoning the one thing every Sality bot trusts: its own peer list. Every Sality bot keeps a list of "super peers," publicly reachable infected machines that form the P2P backbone, and it refreshes that list every 40 minutes. The operation exploited exactly that habit: researchers invalidated the legitimate super peers, swapped in defender-controlled sinkholes, and waited for infected machines to come online on their normal maintenance cycles so the remaining legitimate peers could be purged. The bots are now unreachable for new commands or payloads. The design pattern that got called resilient for years — P2P, no central server to seize — had a maintenance schedule, and it turned out to be exploitable.

The economics of the whole enterprise are almost boring, which is part of what made it work. For the past eight years, Sality's main payload has been EggJagger, a clipboard hijacker: it watches for anything that looks like a cryptocurrency wallet address copied to the clipboard and silently swaps it for an address the operator controls — no prompt, no warning. Copy a Bitcoin or Ethereum address to make a payment, and the funds quietly go somewhere else. CrowdStrike estimates the operator made at least $150,000 that way over the run, and the botnet also powered a handful of DDoS campaigns, including one against a Ukrainian web forum on February 25, 2022 — a day after Russia's invasion began — and one against a Russian crypto exchange that looked like a personal grudge over a transaction. One operator, quietly running one network for 23 years. The quietness was the product.

Source article image
Source image 1

Here's the part worth sitting with, though: a takedown that severs the control channel doesn't clean anything. Most of Sality's 15,000 hosts sit behind NATs and firewalls where they can't be touched from the outside, and they're now orphaned — infected, dormant, peer lists purged, with no command channel to wake them up. The malware is still on the disk. It'll stay there until the operator comes back, probably the same operator, rebuilding on fresh super peers. That's the uncomfortable tradeoff in sinkhole operations like this one: you win the network war and lose the endpoint war, and the infected machines become a long shelf of landmines. If your environment involves copying crypto addresses by hand — exchanges, treasuries,

Source article image
Source image 2
the ops teams of smaller crypto startups — it's worth running a YARA sweep for the Sality components and double-checking where funds actually landed. The botnet is dead; the machines it infected aren't. If you found out one of your hosts had been quietly clipjacking crypto addresses for three years, what would you change first?

Sources

Comments

Popular posts from this blog

AI Is Starting to Feel Less Like a Gadget and More Like Infrastructure

When Two AI Bots Finally Learned to Talk in Discord

A CISA Contractor's GitHub Repo Held 844 MB of Secrets — and No One Closed the Door