23-Year-Old Sality P2P Botnet Disrupted
After 23 years of operation, the Sality peer-to-peer (P2P) botnet has been disrupted as part of an international law enforcement effort.
First observed in 2003, Sality has been used for distributing various malware families, including information stealers, proxy services, distributed denial-of-service (DDoS) payloads, and more.
For the past eight years, it mainly served the EggJagger clipjacking tool, which is believed to have stolen at least $150,000 in Bitcoin and Ethereum.
Sality remained active due to its architecture: it spread through a file infector, attaching itself to executables on disk and removable media, and did not rely on a central command-and-control (C&C) server for receiving code updates.
The protocol behavior that allowed the botnet to persist for over 20 years was also the weakness that led to its demise: it blindly trusted the peers on the network, without authentication or identity verification.
Sality bots periodically checked if the peers in their...
Copyright of this story solely belongs to securityweek.com. To see the full text click HERE