$ techbeacon▋
Darkweb

Long‑running Sality Botnet Shut Down After More Than Two Decades of Global Infections

Long‑running Sality Botnet Shut Down After More Than Two Decades of Global Infections

International law‑enforcement agencies, in partnership with cybersecurity firm CrowdStrike and the nonprofit Shadowserver Foundation, announced the dismantling of the Sality botnet on Monday. The network, which originated in Russia, had compromised over 11 million computers worldwide during a 23‑year campaign, making it one of the longest‑operating malware infrastructures still active today.

First identified in the early 2000s, Sality spread primarily through malicious executable files that masqueraded as legitimate software. Once installed, the malware linked infected machines into a peer‑to‑peer network, allowing its operators to distribute additional payloads, exfiltrate data, and launch coordinated attacks such as distributed denial‑of‑service (DDoS) operations. Over its lifespan, the botnet evaded detection by continually updating its code and leveraging compromised domains to command and control its vast array of endpoints.

The coordinated takedown was the result of months of joint investigation. CrowdStrike provided technical expertise to trace the botnet’s command infrastructure, while Shadowserver contributed network‑level intelligence that helped pinpoint the servers hosting the control traffic. Law‑enforcement officials then moved to seize the identified servers and disrupt the communication channels that kept the botnet functional.

“The removal of Salium’s command and control nodes effectively neutralizes the threat to the millions of devices still infected,” a CrowdStrike spokesperson said in a statement released on Tuesday. The announcement underscored the collaborative model that has become increasingly common in combating sophisticated cyber threats, where private security firms and public agencies pool resources and share intelligence.

Security experts note that while the Sality botnet’s core infrastructure has been taken down, remnants may linger on compromised machines that have not yet been cleaned. They advise users and organizations to run up‑to‑date anti‑malware tools, apply security patches, and monitor network traffic for any signs of residual malicious activity. The takedown also serves as a reminder that even long‑standing threats can persist without vigilant defense measures.

Looking ahead, authorities plan to continue monitoring the affected networks for any attempts to resurrect the botnet under a new guise. The operation highlights the ongoing need for international cooperation in addressing cybercrime, especially as adversaries adapt to evolving security landscapes.

Source: CyberScoop
Deepak Chandra Meena — Deepak covers the dark web and underground hacking forums, reporting on marketplace activity and access broker listings. Monitors Tor-based forums and encrypted leak channels.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related