International Task Force Dismantles Decade-Old Sality Botnet
International law‑enforcement agencies from the United States and Europe announced Friday that they had successfully crippled the Sality botnet, a malware network that has been active for more than a decade. By hijacking its peer‑to‑peer communication channels, officials say they were able to isolate thousands of compromised computers and cut off the botnet’s command structure.
Sality first appeared in the early 2000s as a file‑infector that spread through removable drives and network shares. Over the years it evolved into a sophisticated peer‑to‑peer botnet, used to distribute spam, launch denial‑of‑service attacks and deliver ransomware. Its resilience stemmed from the lack of a central server; each infected host acted as both client and relay, making traditional takedown methods difficult.
The recent operation turned that very resilience into a weakness. Researchers injected specially crafted packets into the botnet’s overlay network, causing the infected nodes to receive false routing information. The trick forced the network to partition itself, effectively isolating individual machines from the control servers that the criminal operators rely on to issue new commands.
According to the joint statement, the maneuver removed the ability of the operators to coordinate at least several thousand machines that were active worldwide. While exact numbers remain classified, the disruption is described as the most extensive interference with Sality’s infrastructure since its emergence. The affected computers, many of which were home PCs and small‑business systems, will now be unable to receive further payloads until cleaned.
The takedown was the result of a coordinated effort between the U.S. Department of Justice, the Federal Bureau of Investigation, Europol’s European Cybercrime Centre and national law‑enforcement units in several member states. Officials highlighted that sharing technical intelligence and legal tools across borders was essential, echoing similar collaborations that dismantled other long‑standing threats such as Gameover Zeus and TrickBot.
Authorities caution that the removal of Sality’s command layer does not automatically eradicate the malware from infected hosts. Victims are still urged to run reputable antivirus tools, apply security patches and consider professional remediation. The operation also serves as a reminder that peer‑to‑peer botnets can be neutralized, but the underlying tactics continue to evolve, prompting ongoing vigilance from both the security community and law‑enforcement partners.
Comments (0)
Be the first to comment.
Join the discussion