AUTO-UPDATED

CrowdStrike and the FBI are dismantling Sality after 23 years

US law enforcement and cybersecurity firm CrowdStrike have dismantled Sality, a persistent 23-year-old botnet that infected global computer systems to facilitate spam, cryptocurrency theft, and distributed denial-of-service attacks.

Key Points

  • CrowdStrike reverse-engineered the botnet and injected false data to force infected machines to disconnect from their criminal controllers.
  • The FBI and the U.S. Department of Justice supported the operation by seizing web domains used to manage the botnet's infrastructure.
  • Sality utilized a decentralized, peer-to-peer architecture and infected executable files, allowing it to evade detection and remain active since 2003.
  • The botnet served as a gateway for cybercriminals to gain unauthorized access to industrial systems, small businesses, and public sector networks.
  • No arrests have been announced, and the total number of infected machines or financial losses remains undisclosed by authorities.

Why it Matters

This operation highlights the ongoing threat posed by legacy malware that remains undetected on unpatched systems for decades. It also signals a shift toward more aggressive, offensive cybersecurity tactics where private firms actively disrupt criminal networks by manipulating their internal communications.
The Next Web Published by Ana-Maria Stanciuc
Read original