CrowdStrike and US Authorities Disrupt Russia-Based Sality Botnet After Two Decades

· · Views: 2,439 · 3 min time to read

A Russia-based cybercrime operation that survived for more than two decades is being dismantled through a coordinated effort involving CrowdStrike, U.S. authorities and European law enforcement, exposing how difficult peer-to-peer botnets can be to eliminate even years after their emergence.

The hacking operation, known as Sality, was first spotted in 2003 and became one of the internet’s longest-running cybercriminal enterprises.

U.S. News also reported on the two-decade-old Russian hacking operation as U.S. officials and CrowdStrike moved to dismantle its infrastructure.

Authorities seize infrastructure behind Sality

U.S. officials said they had seized web domains used by the hackers to control compromised computers. Those infected systems could be used to send spam, conduct distributed denial-of-service attacks or steal cryptocurrency. CrowdStrike, meanwhile, said it had separated a network of infected machines from the operator controlling them.

CrowdStrike began dismantling the botnet on August 31 during its Day Zero threat intelligence summit in Las Vegas. The FBI and U.S. Justice Department said the operation was coordinated with European law enforcement and other organizations.

First Assistant United States Attorney Bill Essayli described cybercriminals, botnets and malware as a “clear and present danger” to U.S. security and the economy. The Justice Department identified Sality as Russia-based, although it offered no additional detail about its location or operators.

CrowdStrike turned Sality’s architecture against itself

The operation was difficult to disrupt because Sality did not depend entirely on a conventional centralized command system.

Reuters reported that its peer-to-peer architecture distributed commands across compromised machines, making the network particularly resistant to law-enforcement intervention. CrowdStrike ultimately exploited that design by feeding bogus information into the network, causing parts of the botnet to disconnect themselves from their creator.

CrowdStrike researcher Tillmann Werner shared that it was the company’s most complex botnet takeover, explaining that Sality had been designed specifically to survive attempts at takedown or takeover. Reverse-engineering its structure, identifying weaknesses and building the required disruption infrastructure took extensive technical work.

An old botnet can still create modern security risks

Sality has been overshadowed in recent years by ransomware operations, but age does not necessarily make criminal infrastructure harmless.

David Watson, director of nonprofit security organization The Shadowserver Foundation, which participated in the takedown, shared that Sality was “quite old-school” but remained a vector into a lot of organization. Its creator has not been publicly identified, leaving investigators watching for attempts to regain control or rebuild the network.

For cybersecurity teams, the Sality operation demonstrates why dismantling malicious infrastructure is not simply about taking individual servers offline. Decentralized architectures can survive interventions precisely because resilience is engineered into them.

That makes the takedown relevant beyond one aging malware family. For defenders and security infrastructure builders, Sality shows that successful disruption increasingly depends on understanding an attacker’s architecture deeply enough to turn its own resilience mechanisms into weaknesses.

Share
f 𝕏 in
Copied