Skip to main content
Emerging ThreatsMalware & Ransomware

US-Led Operation Disrupts Sality P2P Botnet Infrastructure

Law enforcement operations room with map, computers, and team working together.

“In the weeks leading up to the latest disruption, this cooperation intensified, with partners holding weekly operational calls to coordinate their actions,” Europol said — a description of the orchestration behind an international strike that, on August 31, significantly disrupted a peer-to-peer malware network that has operated for more than two decades.

The August 31 operation

On August 31, a US-led law enforcement operation targeted the Sality peer-to-peer (P2P) botnet. The action brought together authorities from Bulgaria, Hungary, Romania and the United States, and was supported by Europol and private-sector partners CrowdStrike and the Shadowserver Foundation. Authorities in the US and Europe focused on seizing Sality-linked domains, while other partners moved to identify and remediate infected machines.

How sinkholing and protocol-level manipulation worked

The disruption relied on two linked technical moves: removing legitimate peers from infected machines’ peer lists through protocol-level manipulation, and inserting sinkhole entries into the emptied lists so communications could be redirected. CrowdStrike described the underlying vulnerability this way: “Every Sality bot maintains a finite list of known super peers, which are publicly reachable infected machines that form the backbone of the P2P network.”

CrowdStrike further spelled out the botnet’s maintenance cadence: “Every 40 minutes, it verifies whether its stored peers are still online. Peers that respond accumulate reputation; those that fail to respond lose reputation and are eventually purged.” The disruption exploited that trust-and-reputation mechanism to replace purged entries with sinkholes, enabling tracking of infected endpoints and the notification of victims.

Scale and impact: machines, IPs and malicious payloads

Europol said Sality has operated for more than 20 years and at its peak featured over one million infected machines. Over the course of the past two decades, more than 11 million unique IP addresses have been linked to the infrastructure, Europol added. CrowdStrike reported that the botnet’s operator used it to distribute malicious payloads to over 15,000 infected machines, including credential theft tools, spam distribution, proxy services, network exploitation and distributed denial-of-service (DDoS) attacks.

Roles played by law enforcement, vendors, and CSIRTs

Europol described its contribution as long-term support for identifying and taking down Sality infrastructure worldwide, noting continued engagement since 2017 and coordination across jurisdictions in the weeks before the disruption. The Shadowserver Foundation coordinated with internet service providers (ISPs) and Computer Security Incident Response Teams (CSIRTs) to identify infections, notify victims and assist with remediation, the US Justice Department said. CrowdStrike provided the technical analysis of Sality’s peer mechanics that enabled the protocol-level intervention.

What this means for technologists, affected enterprises, and ISPs

  • Technologists and security teams: will monitor whether sinkhole entries and domain seizures yield persistent control and continued visibility into the botnet’s footprint, and will need to verify remediation on endpoints after notification from Shadowserver and CSIRTs.
  • Affected enterprises and endpoint owners: should expect notification and remediation assistance where infections are identified; CrowdStrike’s assessment that over 15,000 machines received malicious payloads underscores the kinds of follow-up remediation that may be required.
  • ISPs and CSIRTs: having been directly coordinated by the Shadowserver Foundation, they will continue to be the primary channels for notification and remediation of infected users identified through sinkholing and domain seizures.

The operation demonstrates a concrete way to disrupt decentralized botnets by attacking the trust mechanics that sustain P2P networks rather than searching for a single command-and-control node. Europol’s timeline — sustained engagement since 2017 and weekly operational calls in the run-up to August 31 — shows the patience and coordination required to pull such an effort together. Whether the disruption yields long-term attrition of Sality or simply forces its operators to adapt will depend on the durability of the sinkholing and the follow-through of remediation efforts across ISPs and CSIRTs.

Source: https://www.infosecurity-magazine.com/news/international-operation-disrupts/