Russian Sality malware network dismantled: Romania among countries involved
The FBI and US Department of Justice commend Romania, Bulgaria and Hungary after the dismantling of the Sality botnet, which had over 11 million infected IP addresses.

International operation shuts down Sality botnet linked to Russia
Romania, Bulgaria and Hungary participated in a multinational operation that neutralised the infrastructure of the Sality malware, a botnet network with Russian connections through which cyber crimes were committed over more than two decades, according to G4Media, citing the Rador agency and SEGA Bulgaria sources.
The operation was officially announced through a statement by the US Department of Justice, in cooperation with private partners CrowdStrike and Shadowserver Foundation.
Botnet active since 2003 with millions of compromised devices
The Sality network has infected devices with malicious software at least since 2003, enabling cryptocurrency theft, cyber attacks and the sending of spam messages against victims in the United States and other countries. The infected computers formed a decentralised peer-to-peer (P2P) network, controlled by an operator and used for coordinated theft and attack activities.
At its peak, the botnet gave hackers simultaneous access to over one million infected computers. To date, over 11 million unique IP addresses have been associated with the dangerous infrastructure used for distributing the malware.
Server and domain seizures in the US and Europe
As part of the international operation, the FBI, the Department of Justice and DCIS seized servers and domains linked to Sality on US territory. European partners from Bulgaria, Hungary and Romania took action against other domains hosted in Europe.
Critical assistance was provided by the Bulgarian General Directorate for Combating Organised Crime, the Hungarian National Bureau for Investigating Cybercrime, the Romanian Police through the Directorate for Combating Organised Crime and the Central Cybercrime Unit, as well as by Eurojust and Europol.
Statements from American authorities
"Cyber criminals, botnets and malware programmes represent a clear and imminent threat to the security and economy of our nation," said Bill Essayli, First Deputy Attorney General of the United States. "This successful effort to eliminate the Sality botnet demonstrates that, working together, public and private sectors can be a powerful force for good."
Patrick Grandy, Assistant Director responsible for the FBI's local office in Los Angeles, emphasised that the operation strengthens the institution's cybersecurity capabilities. "The FBI will continue to work with our partners to prevent further cyber attacks and theft from victims in the United States," Grandy added.
"Sinkholing" technique isolated infected devices
The neutralisation of the Sality botnet was achieved through a specialised "sinkholing" operation: traffic from infected computers was diverted away from criminal servers, isolating the compromised devices and rendering the hackers' command channel completely unusable.
Europol also confirmed the operation, announcing that the dangerous global cyber network Sality had finally been defeated after more than two decades of criminal activity. The criminal infrastructure had infected and controlled millions of computers worldwide.
Source: G4Media