$ techbeacon▋
DDoS

International Coalition Cracks Down on Sality Botnet, Redirects Infected Machines

International Coalition Cracks Down on Sality Botnet, Redirects Infected Machines

An operation coordinated by U.S. law enforcement agencies and partner nations has successfully taken control of thousands of computers compromised by the Salium (Sality) peer‑to‑peer botnet, effectively cutting off its command infrastructure.

The effort, described by officials as a "sinkhole" deployment, rerouted traffic from infected hosts to servers under the control of the investigators. By doing so, the authorities can monitor the botnet’s activity, prevent further malicious commands from reaching the compromised devices, and gather data to aid future prosecutions.

Sality, first observed in the mid‑2000s, has long been a staple of the cybercrime ecosystem. Its decentralized design allowed it to survive takedowns that crippled more centrally managed networks, and it has been linked to a range of illicit activities, from distributing ransomware to stealing personal information. Over the years, the botnet has evolved, incorporating new infection vectors and maintaining a resilient peer‑to‑peer communication model.

The current sinkhole operation involved collaboration among multiple agencies, including the U.S. Department of Justice, the Federal Bureau of Investigation, and international partners such as Europol and law‑enforcement bodies in the United Kingdom and Germany. Technical teams deployed a network of redirect servers that mimic the botnet’s command‑and‑control endpoints, luring compromised machines to report to the controlled infrastructure instead of the criminal operators.

According to the agencies, the sinkhole has already intercepted traffic from an estimated several thousand devices worldwide. While the exact number of machines taken offline remains classified, the operation is considered one of the most extensive actions against a peer‑to‑peer botnet to date.

Experts note that sinkholing does not immediately remove malware from infected computers, but it does prevent the botnet from issuing further instructions, such as downloading additional payloads or launching coordinated attacks. Users whose systems have been redirected are urged to run reputable antivirus tools, apply security patches, and consider professional remediation to fully eradicate the threat.

The disruption of Sality underscores a broader trend of increased international cooperation in cybercrime enforcement. As botnets become more sophisticated and distributed, authorities are turning to joint operations that combine legal authority, technical expertise, and cross‑border intelligence sharing.

Looking ahead, investigators say they will continue to monitor the sinkhole traffic to map the botnet’s remaining nodes and identify the individuals behind its operation. The data collected may support criminal charges and help prevent the emergence of successor networks that could adopt Sality’s resilient architecture.

Arjun Pratap Rana — Arjun reports on data breaches and corporate security incidents, focusing on how leaks happen and what they mean for affected users. Verifies claims against HaveIBeenPwned and leak listings.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related