U.S. Authorities and CrowdStrike Dismantle Sality Botnet
U.S. law enforcement and CrowdStrike dismantled Sality, a Russian-based hacking operation that had operated for over two decades.
U.S. law enforcement and the cybersecurity firm CrowdStrike dismantled Sality, a Russian-based hacking operation that had functioned for more than 20 years. First identified in 2003, the botnet utilized a peer-to-peer architecture to steal cryptocurrency, send spam, and execute distributed denial-of-service attacks.
The takedown involved a coordinated effort between the United States Department of Justice, the Federal Bureau of Investigations, and European law enforcement. While U.S. officials seized critical web domains, CrowdStrike performed a technical operation to seed the network with bogus information, tricking compromised computers into disconnecting from the botnet's mastermind. The Shadowserver Foundation also provided assistance in the operation.
CrowdStrike executed the final dismantling during its Day Zero threat intelligence summit in Las Vegas. Although the creator of the botnet has not been publicly identified, First Assistant United States Attorney Bill Essayli characterized the operation as a necessary response to a clear danger to the national security and economy of the United States.