A US-led international law enforcement operation successfully disrupted the long-running Sality peer-to-peer botnet, which has infected millions of devices globally over the past two decades.
Key Points
- The August 31 operation involved authorities from the US, Bulgaria, Hungary, and Romania, supported by Europol, CrowdStrike, and the Shadowserver Foundation.
- Sality has operated for over 20 years, impacting more than 11 million unique IP addresses through malicious activities like crypto-theft, spam, and DDoS attacks.
- Investigators utilized "sinkholing" to redirect traffic from infected machines, effectively isolating them from the botnet's decentralized command infrastructure.
- Security experts exploited the botnet's peer-verification protocol to remove malicious nodes and replace them with sinkhole entries for victim notification and remediation.