FILE PHOTO: A man holds a laptop computer as cyber code is projected on him in this illustration picture taken on May 13, 2017. REUTERS/Kacper Pempel/Illustration/File Photo

Russian cybercrime operation being dismantled after two decades, US officials and CrowdStrike say

· CNA · Join

Read a summary of this article on FAST.
Get bite-sized news via a new
cards interface. Give it a try.
Click here to return to FAST Tap here to return to FAST
FAST

LAS VEGAS, Sept 1 : A two-decade-old Russian hacking operation dubbed "Sality" is being dismantled, U.S. law enforcement officials and cybersecurity company CrowdStrike announced on Tuesday. 

U.S. officials said they had seized the web domains hackers used to take over computers to send spam, carry out distributed denial-of-service operations or steal cryptocurrency, while CrowdStrike said it had cut off a network of compromised computers from the mastermind controlling it.

CrowdStrike began dismantling the "botnet" on Monday in front of a live audience at the company’s Day Zero threat intelligence summit in Las Vegas. 

The FBI and U.S. Justice Department said in a pair of statements issued on Tuesday that the operation had been carried out in coordination with European law enforcement and other organizations.

CNA Games

Guess Word
Crack the word, one row at a time

Buzzword
Create words using the given letters

Mini Sudoku
Tiny puzzle, mighty brain teaser

Mini Crossword
Small grid, big challenge

Word Search
Spot as many words as you can
Show More
Show Less

"Cybercriminals, botnets, and malware are a clear and present danger to our nation’s security and economy,” First Assistant United States Attorney Bill Essayli said in a statement announcing the move.

Although it has in recent years been overshadowed by more disruptive ransom-seeking cybercriminals, Sality, first spotted in 2003, remains one of the internet’s longest-running cybercriminal enterprises. 

The Justice Department said it was based out of Russia but did not provide further detail. The Russian Embassy in Washington did not immediately respond to a request for comment.

Sality's peer-to-peer architecture meant it could receive commands through a diffuse network of compromised machines, making it particularly resistant to law enforcement action.

But CrowdStrike said in a blog post published on Tuesday that it turned that strength against Sality by seeding the network with bogus information that tricked the botnet's components into cutting themselves off from their creator.

CrowdStrike researcher Tillmann Werner said that reverse-engineering the botnet's structure, finding weak points and building the infrastructure needed to knock it down had required painstaking work. 

"This was the most complex botnet takeover we have ever done," Werner told Reuters. "This was built to be resilient. It was built to survive takedown or takeover. I think that's the reason it's been around for so long."

David Watson, director of nonprofit security group The Shadowserver Foundation, which was also involved in the takedown, said Sality was "quite old-school" but could still be dangerous.

“It's still a vector into a lot of organizations,” Watson said. 

He said the next step would be to see what, if anything, Sality's creator, who has yet to be publicly identified, did to regain control of or re-create the botnet.

“What does he do?” Watson said. “Does he fight back?”

Source: Reuters

Newsletter

Week in Review

Subscribe to our Chief Editor’s Week in Review

Our chief editor shares analysis and picks of the week's biggest news every Saturday.

Sign up for our newsletters

Get our pick of top stories and thought-provoking articles in your inbox

Subscribe here

Get the CNA app

Stay updated with notifications for breaking news and our best stories

Download here

Get WhatsApp alerts

Join our channel for the top reads for the day on your preferred chat app

Join here