Sality, a Russia-based botnet that infected more than 11 million devices during a 23-year run of operations, was dismantled Monday by law enforcement, CrowdStrike and the Shadowserver Foundation. 

CrowdStrike, which announced the takedown Tuesday alongside authorities, said it played a crucial role dismantling the botnet’s technical infrastructure, rendering the malware-spreading operation irrecoverable. 

The peer-to-peer botnet was a persistent piece of criminal infrastructure that evaded disruption for an exceptionally long period because it lacked centralized architecture. 

Sality used infected machines to communicate peer-to-peer, creating a decentralized structure that made system-wide disruption efforts more difficult than botnets that rely on a core server. 

“The same properties that made Sality resilient also created the conditions for its undoing,” CrowdStrike wrote in a blog post. The company said it targeted Sality’s peer list of infected machines and tricked the network into permanently cutting off access to those devices.

“From the operator’s perspective, infected machines simply disappear,” CrowdStrike wrote, adding that the botnet is no longer under the operator’s control.

Sality’s domains were seized by a globally coordinated effort supported by the FBI, Justice Department and authorities from Europol, Bulgaria, Hungary and Romania, officials said. Shadowserver is working with internet service providers to identify devices infected by Sality and aid with remediation. 

“Cybercriminals, botnets, and malware are a clear and present danger to our nation’s security and economy,” Bill Essayli, first assistant U.S. attorney, said in a statement. 

Europol said the Sality takedown was the culmination of work spanning global law enforcement back to 2017. 

CrowdStrike said Sality’s operator was primarily financially motivated, but it attributed three DDoS attacks to Sality, suggesting the operator was occasionally willing to use the botnet for personal or political aims. 

The botnet enabled cryptocurrency theft and cyberattacks on victims in the United States and abroad, the Justice Department said. Officials did not name the person or cybercrime group behind Sality.

“This operation demonstrates that peer-to-peer architecture, long considered a shield against disruption, is not invincible,” CrowdStrike wrote. 

“Operating for decades without consequence does not mean operating without risk,” the company added. “The calculus has changed. We will find you, we will dismantle your infrastructure, and we will impose costs that make the enterprise untenable.”

The post Dogged Russia-based botnet dismantled after 23-year run appeared first on CyberScoop.