US law enforcement and cybersecurity firm CrowdStrike have dismantled Sality, a persistent 23-year-old botnet that infected global computer systems to facilitate spam, cryptocurrency theft, and distributed denial-of-service attacks.
Key Points
- CrowdStrike reverse-engineered the botnet and injected false data to force infected machines to disconnect from their criminal controllers.
- The FBI and the U.S. Department of Justice supported the operation by seizing web domains used to manage the botnet's infrastructure.
- Sality utilized a decentralized, peer-to-peer architecture and infected executable files, allowing it to evade detection and remain active since 2003.
- The botnet served as a gateway for cybercriminals to gain unauthorized access to industrial systems, small businesses, and public sector networks.
- No arrests have been announced, and the total number of infected machines or financial losses remains undisclosed by authorities.