THE Sality peer-to-peer (P2P) botnet, operational for 23 years, has been disrupted through a coordinated international law enforcement effort involving CrowdStrike and several countries. Originally emerging in 2003, Sality was infamous for distributing various malware types, including DDoS payloads and information stealers, and was notably linked to the EggJagger clipjacking tool, which estimated losses of $150,000 in cryptocurrency.
Its decentralized architecture allowed it to thrive without a central command server but also led to its downfall due to lack of authentication. CrowdStrike's strategy involved manipulating the peer list to isolate infected machines, effectively cutting off the botnet's communication, while law enforcement took down hosting URLs. The Shadowserver Foundation is assisting in identifying and cleaning up botnet victims.