AUTO-UPDATED

International Operation Disrupts Sality P2P Botnet

A US-led international law enforcement operation successfully disrupted the long-running Sality peer-to-peer botnet, which has infected millions of devices globally over the past two decades.

Key Points

  • The August 31 operation involved authorities from the US, Bulgaria, Hungary, and Romania, supported by Europol, CrowdStrike, and the Shadowserver Foundation.
  • Sality has operated for over 20 years, impacting more than 11 million unique IP addresses through malicious activities like crypto-theft, spam, and DDoS attacks.
  • Investigators utilized "sinkholing" to redirect traffic from infected machines, effectively isolating them from the botnet's decentralized command infrastructure.
  • Security experts exploited the botnet's peer-verification protocol to remove malicious nodes and replace them with sinkhole entries for victim notification and remediation.

Why it Matters

This operation marks a significant blow to a persistent cyber threat that has facilitated widespread credential theft and network exploitation for two decades. By dismantling such a resilient, decentralized infrastructure, law enforcement demonstrates an increasing ability to coordinate complex, multi-jurisdictional responses against long-standing criminal botnets.
Infosecurity Magazine Published by Phil Muncaster
Read original