BlackTree Security · Infrastructure · Automation · AI

Authorities Turned Sality’s Own Peer-to-Peer Network Against It

Sality survived for more than two decades by avoiding the single point of failure that brings down many botnets. Its infected machines exchanged commands through a peer-to-peer network, so there was no central server for authorities to seize.

On 31 August, an international public-private operation turned that resilience against the operators. Investigators redirected the botnet’s own peer-to-peer traffic into controlled sinkholes, breaking the communication path between infected devices and their criminal controllers.

Eleven million IP addresses touched the network

Europol says more than 11 million unique IP addresses have been linked to Sality over its lifetime. At its peak, roughly one million systems were infected. The malware combined file-infection techniques with a decentralised command channel, helping it spread and persist across generations of Windows systems.

Those numbers are not the same as 11 million simultaneously infected computers. Dynamic addressing, reinfection and long collection periods can inflate unique-IP counts. They still show the extraordinary reach of a botnet that kept finding new victims long after many defenders considered it old.

There was no headquarters to raid

A central command server gives law enforcement a clear technical target. Peer-to-peer networks are harder because each infected machine can help distribute information to others. Removing one node changes little.

The disruption instead interfered with how Sality’s peers discovered and trusted command information. By steering that traffic into sinkholes, the operation deprived the controllers of their normal update and instruction channel while giving investigators visibility into the remaining population.

A long-running international operation

The US-led action included authorities and partners in Bulgaria, Hungary and Romania, with support from Europol, CrowdStrike and the Shadowserver Foundation. Europol said it had been involved in work against Sality since 2017.

That timeline matters. Botnet disruption is rarely a single dramatic seizure. Investigators need protocol knowledge, infrastructure access, legal coordination and a plan for infected systems scattered across many jurisdictions. The public action is often the visible end of years of preparation.

Disrupted does not mean eradicated

Sinkholing can separate infected machines from the operator, but it does not remove malware from every victim. Organisations may still have compromised endpoints that need to be found, rebuilt and monitored. Criminal developers can also attempt to change discovery mechanisms or establish new infrastructure.

Network defenders should treat any connection to a Sality sinkhole as an incident signal, not evidence that the problem has solved itself. Investigate the endpoint, isolate it, check shared storage for infected executable files and review adjacent systems for spread.

The takedown also shows the value of keeping detections for older malware families. A threat does not become harmless because its name disappears from daily headlines. Sality endured because enough unpatched and unmanaged systems remained available to keep its network alive.

Its peer-to-peer design bought the operators years of resilience. In the end, the same network became the path authorities used to cut them off.

Reference

Leave a Reply

Your email address will not be published. Required fields are marked *