CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Dogged Russia-based botnet dismantled after 23-year run

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5589

As cited

Copy frozen at (site build).

threat intel

Dogged Russia-based botnet dismantled after 23-year run

Law enforcement, CrowdStrike, and the Shadowserver Foundation dismantled Sality, a Russia-based peer-to-peer botnet that had infected more than 11 million devices. CrowdStrike targeted the botnet's peer list and tricked the network into permanently severing operator access to infected machines, rendering the infrastructure unrecoverable. A coordinated effort involving the FBI, Justice Department, and authorities from Bulgaria, Hungary, Romania, and Europol seized Sality's domains and is working to identify and remediate infected devices.

Why it matters: Organizations and Internet service providers operating globally need to check for Sality infections in their networks, as the botnet was used for cryptocurrency theft and distributed denial of service (DDoS) attacks affecting victims in the United States and abroad.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Dogged Russia-based botnet dismantled after 23-year run

Law enforcement, CrowdStrike, and the Shadowserver Foundation dismantled Sality, a Russia-based peer-to-peer botnet that had infected more than 11 million devices. CrowdStrike targeted the botnet's peer list and tricked the network into permanently severing operator access to infected machines, rendering the infrastructure unrecoverable. A coordinated effort involving the FBI, Justice Department, and authorities from Bulgaria, Hungary, Romania, and Europol seized Sality's domains and is working to identify and remediate infected devices.

Why it matters: Organizations and Internet service providers operating globally need to check for Sality infections in their networks, as the botnet was used for cryptocurrency theft and distributed denial of service (DDoS) attacks affecting victims in the United States and abroad.

VendorsCrowdStrike
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary