Sality’s peer-to-peer design carried the seed of its own takedown

US and European agencies sinkholed the 23-year-old Sality botnet by poisoning the peer lists its infected machines trust.

CSBadmin
2 Min Read

After a coordinated takedown on August 31, the Sality botnet can no longer push payloads to the machines under its control. United States, Bulgarian, Hungarian, and Romanian authorities ran the operation with CrowdStrike and the Shadowserver Foundation, and the Department of Justice announced the outcome on Tuesday.

The botnet’s roots go back more than two decades. Its core routine grafts itself onto executable files and travels when those files move between machines, whether over office networks, USB sticks, or download sites. Two surviving P2P fleets, labeled version 3 and version 4, shared code but spoke incompatible protocols, and CrowdStrike puts the combined size at more than 15,000 machines. Payloads over the years spanned credential stealers, spam tools, proxy services, and distributed denial-of-service firepower.

Its recent workhorse was EggJagger, a clipboard clipper that rewrites copied cryptocurrency addresses to ones owned by the operators, who have banked at least $150,000 that way. To kill the network, defenders exploited Sality’s blind trust: bots refresh their lists of super peers every 40 minutes and accept any machine that answers the P2P handshake. Sinkhole nodes were swapped in for legitimate peers, leaving infected hosts able to reach only defenders, and the domains serving Sality payloads were seized in the US and Europe.

The operators, believed to work from Russia and tracked under names such as Salty Spider and Kukacka, also aimed the botnet at DDoS targets, including a Ukrainian forum hit one day after the February 2022 invasion. Infected machines now beacon to defender-run sinkholes, and CrowdStrike suggests hunting UDP traffic toward the lighthouse address 188.166.101.148 as a sign of infection.

CrowdStrike noted the closing irony: the open design that made Sality resilient to conventional command-and-control takedowns is precisely what let defenders turn the network against itself.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.