Sality, a peer-to-peer botnet with the staying power of a cockroach, is finally dead.
The DOJ and international cyber police announced this week they struck a decisive blow against Sality. For the past 23 years the notorious botnet has quietly infected machines and enabled cryptocurrency theft. While the operators behind the botnet remain unidentified and at large, authorities say the once bulletproof botnet enabling decades of cybercrimes was slayed by a protocol-level trick verses a SWAT-style midnight raid or pulling a single-point-of-failure plug.
To dismantle the operation, the DOJ said it partnered with the FBI, DCIS (the Defense Criminal Investigative Service), and law enforcement agencies in Hungary, Romania, and Bulgaria.
“Cybercriminals, botnets, and malware are a clear and present danger to our nation’s security and economy,” said First Assistant U.S. Attorney Bill Essayli. “This successful effort to take down the Sality botnet shows that by working together the public and private sectors can be a powerful force for good.”
According to a Tuesday release by the DOJ, Sality has been operating since 2003 and has enabled cryptocurrency theft, malware distribution, cyberattacks on victims, and functioning as the backbone for the crooks behind the botnet.
The malware used a peer-to-peer model in which infected machines communicated directly with one another to share commands, rather than relying on centralized command and control servers. This decentralized structure allowed the botnet to run covertly, often without any indication to victims that their machines had been compromised.
Sality Malware: Short History
Sality started out much simpler than the botnet DOJ dismantled this week. Symantec researchers first identified it in June 2003 as a basic file-infecting virus that attached itself to Windows executable files and spread whenever an infected file was copied to a network share, USB drive, or shared over a file-sharing network.
Its original payload was a modest keylogger that pulled passwords from the Windows registry and dial-up connection settings and emailed them to the attacker through SMTP servers based in Russia. Symantec later traced the malware’s name to Salavat City, a Russian town the author may have originated from. The code also carried the author’s self-given nickname, “Sector,” and a second alias, “Kuku,” Russian for “hide-and-seek.”
Between 2004 and 2008, Sality got sneakier. Its authors made the code polymorphic and split the payload from the virus itself, so infected machines fetched malware from hardcoded URLs instead of carrying it directly. This setup had one obvious flaw. When you block the URL the infection went dead.
Around 2008, the authors fixed that by adding the peer-to-peer component which let infected machines pull instructions from each other instead of a fixed address, according to Symantec. This was a defining characteristic that defined Sality to this day.
According to CrowdStrike, whose Counter Adversary Operations team led the technical side of this week’s takedown, that backbone connected more than 33,000 infected machines at the time of disruption.
For most of its history, Sality’s operator used the botnet as a distribution hub for credential stealers, spam tools, proxy services, and other payloads, sending each to machines that kept multiplying on their own.
For the past eight years, its primary payload has been EggJagger, a tool that watches an infected machine’s clipboard for copied cryptocurrency wallet addresses and quietly swaps in one the operator controls, redirecting funds when the victim completes a transfer. CrowdStrike estimates EggJagger alone generated at least $150,000 in stolen cryptocurrency.
The Botnet was a Moneymaker and Then Some
CrowdStrike’s Monday writeup ties Sality to three separate denial-of-service attacks that look more personal or political than profit-driven. Incidents include a 2016 attack on an Arabic-language financial forum, a February 2022 attack, launched one day after Russia’s invasion of Ukraine. In Sept. 2023, CrowdStrike attributed an attack on a Russian cryptocurrency exchange that was impressively compiled and launched within seconds.
Most botnet takedowns are a rounding error for adversaries. Block a C2 server, watch a smaller network of infected toasters and routers wink out. Sality was different, according to researchers. It was a self-sustaining, leaderless network that survived over time, evolving with each decade’s malware trends – from spam to ransomware to crypto theft – and at least one earlier law enforcement run at it.
Because Sality had no head to cut off, every infected machine was both client and potential server. That meant there was no central point authorities could seize to kill the whole network at once.
Subsequently, prior attempts to thwart Sality proved ineffective.
To Kill a Cockroach
Sality’s eventual downfall was a protocol-level trick, not a raid.
On Monday, August 31, a day before the DOJ’s announcement, CrowdStrike exploited Sality’s own peer-to-peer design rather than targeting infrastructure it never had.
Because every infected machine kept a list of “super peers” that Sality operators checked in with for commands, CrowdStrike was able to disrupt those check-ins by replacing legitimate ones with sinkholes it controlled. This cut the operator off from every device on the network.
“From the operator’s perspective, infected machines simply disappear,” CrowdStrike wrote. In parallel, the Justice Department, FBI, and DCIS seized Sality-linked domains in the U.S., while Bulgaria, Hungary, and Romania acted against domains in Europe.
Sality was stopped at the infrastructure point. No arrests, indictments, or extraditions came with it, and the DOJ named no defendant. It’s unclear whether the operator, tracked by CrowdStrike under an internal codename, will face charges.
Takes a Village
CrowdStrike, for its part, isn’t waiting on an indictment to have the last word: “We will find you, we will dismantle your infrastructure, and we will impose costs that make the enterprise untenable,” the company wrote, addressing the operator directly.
The DOJ credited private-sector partners CrowdStrike and Shadowserver Foundation for the takedown. For its part, Shadowserver Foundation is now working with internet service providers to notify infected victims. Europol, which coordinated the European side of the operation, says the effort to dismantle Sality dates back to 2017.
“This unique collaboration among international law enforcement and private sector partners only enhances the FBI’s cyber security capabilities and our efforts to neutralize the threat posed by the Sality botnet,” said Patrick Grandy, the Assistant Director in Charge of the FBI’s Los Angeles Field Office.