FBI shuts down Sality botnet network
US, European, and private-sector investigators disrupted Sality, a peer to peer botnet that has run for more than 20 years and was still controlling over 15,000 infected computers. Authorities redirected infected machines away from the criminal network instead of arresting a single operator.
- Report priority
- Medium
How it works
Investigators exploited a trust flaw in how Sality bots pick partners: each infected machine keeps a list of other infected "super peer" machines and checks every 40 minutes whether they still respond, so authorities made the botnet's own peers go silent and then fed each infected machine sinkhole addresses instead, redirecting it away from real criminal...
What to do
Follow any remediation instructions your ISP or national CSIRT sends about Sality, and run a full malware scan with updated antivirus software if you have any reason to think an old, unpatched Windows machine may be infected.
Technical details
Sality is a decentralized P2P botnet in which each infected host maintains a list of publicly reachable "super peer" bots and re-checks their availability roughly every 40 minutes, raising or lowering each peer's reputation based on responsiveness. The takedown team exploited this by causing legitimate super peers to fail verification and get purged from bots' peer lists, then inserting sinkhole addresses into the now-empty slots. This let the coalition (FBI, Europol, Bulgarian, Hungarian, and Romanian authorities, CrowdStrike, and Shadowserver) redirect bot traffic for tracking and victim notification without needing a central C2 server to seize, since Sality has none.