Published 14 hours ago • loading... • Updated 40 minutes ago
Russian Cybercrime Operation Being Dismantled After Two Decades, US Officials and CrowdStrike Say
CrowdStrike said the peer-to-peer malware had infected more than 15,000 machines worldwide and stolen at least $150,000 in cryptocurrency.
On Tuesday, U.S. law enforcement officials and CrowdStrike announced the dismantling of Sality, a 23-year-old Russian hacking operation that utilized a peer-to-peer botnet to deliver malware and steal cryptocurrency worldwide.
First spotted in 2003, Sality operated as a resilient peer-to-peer network for over two decades, infecting more than 15,000 machines to facilitate spam, DDoS attacks, and cryptocurrency theft via the EggJagger tool.
CrowdStrike and international law enforcement disrupted the botnet on Monday by executing a peer-to-peer sinkhole operation, seeding the network with bogus data that tricked compromised machines into severing connections from their creator.
The U.S. Justice Department, FBI, and European law enforcement partners seized Sality-linked web domains, while the Shadowserver Foundation works with Computer Security Incident Response Teams to aid victim notification and remediation.
While the takedown isolated infected machines, cybersecurity experts warn the unidentified creator could attempt to rebuild the botnet, emphasizing that Sality remains a dangerous vector for future cyber-enabled attacks.