U.S. law enforcement agencies and cybersecurity company CrowdStrike said on Tuesday that they have moved to dismantle Sality, a Russian-based hacking operation that has been active for roughly two decades. Officials reported that they seized multiple web domains used by the malware authors to commandeer infected computers to send spam, mount distributed denial-of-service attacks, or steal cryptocurrency.
CrowdStrike said it had also taken steps to sever a network of compromised machines from the botnet's operator. The firm began its technical intervention on Monday as part of a live demonstration at its Day Zero threat intelligence summit in Las Vegas, when researchers deployed measures designed to disrupt the botnet's command infrastructure.
The FBI and the U.S. Department of Justice issued statements on Tuesday saying the operation was conducted in coordination with law enforcement in Europe and with other organizations. First Assistant United States Attorney Bill Essayli emphasized the broader implications in a statement announcing the action: "Cybercriminals, botnets, and malware are a clear and present danger to our nation’s security and economy."
Sality, which was first observed in 2003, has remained among the internet's longest-running cybercriminal operations, even as newer ransomware-focused groups have drawn more attention in recent years. The Justice Department confirmed the botnet was based out of Russia but provided no additional specifics. The Russian Embassy in Washington did not immediately respond to requests for comment.
Part of Sality's resilience stems from its peer-to-peer architecture. That design permitted the botnet to receive instructions through a widely distributed mesh of infected machines, making it notably resistant to traditional law enforcement disruption techniques.
In a blog post published Tuesday, CrowdStrike described how it leveraged those same structural features to neutralize the net. Researchers said they seeded the network with deceptive information that induced elements of the botnet to isolate themselves from their controller.
Tillmann Werner, a researcher at CrowdStrike, described the effort as painstaking and technically demanding. "This was the most complex botnet takeover we have ever done," he said, adding: "This was built to be resilient. It was built to survive takedown or takeover. I think that’s the reason it’s been around for so long."
Nonprofit security group The Shadowserver Foundation, represented by director David Watson, also participated in the takedown. Watson characterized Sality as "quite old-school" but warned it still posed risks to organizations. "It’s still a vector into a lot of organizations," he said.
Watson noted the next phase will involve monitoring to determine whether the unknown author of Sality attempts to regain control of the existing network or to recreate the botnet from scratch. "What does he do?" Watson asked. "Does he fight back?"
The company named in the operation, CrowdStrike Holdings Inc, is commonly identified by the ticker CRWD. The coordinated action combined legal measures to seize control points with technical measures to disrupt the peer-to-peer communications that sustained the botnet.
Summary
A coordinated operation by U.S. authorities, European partners, CrowdStrike, and nonprofit security groups targeted Sality, a peer-to-peer botnet first seen in 2003 and based out of Russia according to the Justice Department. Authorities say they seized web domains used by the malware operators, while CrowdStrike reported it tricked parts of the botnet into severing links with its controller during a live demonstration at its Las Vegas conference. Researchers and security partners will now monitor whether the unidentified creator attempts to retake or rebuild the botnet.
Key points
- Sality is a long-running Russian-based botnet first identified in 2003 and has been targeted for dismantling by U.S. law enforcement and CrowdStrike.
- U.S. officials said web domains used by the operation were seized; CrowdStrike said it cut compromised machines off from the botnet's controller by seeding false information into the network.
- Sectors affected include cybersecurity providers, internet infrastructure and hosting services, and organizations vulnerable to spam, DDoS attacks, or cryptocurrency theft.
Risks and uncertainties
- It is unclear whether the botnet's creator, who has not been publicly identified, will attempt to regain control or reconstitute the network - a risk for any organizations still exposed to remnants of the botnet.
- Because Sality relied on a resilient peer-to-peer design, remnants or variants could continue to pose a threat, affecting internet infrastructure and businesses that rely on robust network security.