Sality, a Russia-based peer-to-peer botnet that infected more than 11 million devices over 23 years, has been dismantled by law enforcement, CrowdStrike, and the Shadowserver Foundation. The takedown used infrastructure seizure and network disruption to cut off the botnet’s control, ending its use in cryptocurrency theft, cyberattacks, and DDoS activity. #Sality #CrowdStrike #ShadowserverFoundation #Europol #FBI
Keypoints
- Sality infected more than 11 million devices during a 23-year campaign.
- Law enforcement, CrowdStrike, and Shadowserver Foundation dismantled its infrastructure.
- The botnet relied on peer-to-peer communication, making disruption difficult.
- CrowdStrike targeted Sality’s peer list to cut infected devices off permanently.
- The botnet was used for cryptocurrency theft, cyberattacks, and some DDoS attacks.