Law enforcement agencies and various security firms have dismantled the Sality botnet. The malware had been active since 2003(!) and, at its peak, infected one million devices. Researchers exploited a flaw in the P2P protocol to remove all super peers from the bots’ peer lists.
Europol and the FBI report that the decades-old Sality botnet was taken offline during an international operation. Over the course of 23 years, more than 11 million unique IP addresses were linked to the botnet’s infrastructure. Eurojust and investigative agencies from Bulgaria, Hungary, and Romania were also involved. CrowdStrike, among others, participated in the investigation as a private security firm.
Sality is a file infector. The malware infects executable files on local drives, shared network folders, and USB drives. If someone opens such a file on an uninfected system, that machine becomes infected as well. Sality can then download additional malware that steals passwords, takes over Wi-Fi routers, or sets up proxy servers. Spam, DDoS attacks, click fraud, and crypto theft via clipper malware were also part of its repertoire.
Trust without verification
According to CrowdStrike, Sality’s ability to survive for so long was due to its decentralized architecture. Bots communicated directly with one another rather than with a central command-and-control server. Starting in 2003, Sality evolved from a classic file-based virus into complex malware, including a polymorphic P2P botnet with keylogging and rootkit capabilities.
However, the P2P protocol proved to be the weak point. Sality bots did not verify each other. There was no authentication, no cryptographic identity, and no allowlist. Any publicly accessible machine that responded correctly to the handshake was considered a legitimate peer.
CrowdStrike describes this as a low-effort method used by Sality to monetize the botnet’s deployment. Everything from credential theft to spam distribution and DDoS attacks was made possible through Sality. This proved quite lucrative: in cryptocurrency alone, the botnet generated the equivalent of nearly one and a half metric tons.
Peer lists drained
Every bot checked every forty minutes to see if its super peers were still online. Any bot that did not respond lost reputation and eventually disappeared from the list. Researchers exploited this mechanism to remove all super peers, after which the bots no longer received instructions. Sinkholes were then inserted into the empty peer lists, which also isolated machines behind a firewall or NAT.
At the same time, the URLs hosting the Sality payloads were taken offline. These addresses were distributed to infected machines via “URL packs.” U.S. authorities seized domains, and European partners simultaneously took the same action against domains hosted in Europe. CrowdStrike states that Sality delivered payloads to over 15,000 machines worldwide.
The Shadowserver Foundation is now working with internet service providers and CSIRTs to detect infected systems and notify victims.
See also: Aisuru botnet breaks DDoS record with 31.4 Tbps attack