CrowdStrike and the FBI are dismantling Sality after 23 years
Sality has been infecting computers since 2003, making it older than the iPhone, Facebook, and much of the security industry now working to dismantle it. US law enforcement and CrowdStrike began taking it apart this week, Reuters reported.
For more than two decades, the operation has been used for fairly ordinary cybercrime. Infected machines have been used to send spam, launch distributed denial-of-service attacks and steal cryptocurrency, with the criminals shifting between them as different opportunities became profitable.
The way authorities took it down is more unusual. CrowdStrike reverse-engineered the botnet, identified weaknesses in its structure, and then seeded it with false information that convinced infected machines to disconnect from their controller.
“This was the most complex botnet takeover we have ever done,” said Tillmann Werner, a CrowdStrike researcher. The company announced the operation at its Day Zero threat intelligence summit in Las Vegas.
Sality managed to survive for...
Copyright of this story solely belongs to thenextweb.com. To see the full text click HERE