The United States, Bulgaria, Hungary and Romania took part in an international operation to neutralize the Sality botnet, a malware infrastructure associated with Russia and used for cybercrime. The action, announced by the US Department of Justice and Europol, targeted servers and domains used to control the network, as well as to distribute the malicious software.
As part of the operation, US authorities, including the FBI and DCIS, seized servers and domains in the United States. In Europe, partners in Bulgaria, Hungary and Romania took action against other domains associated with Sality. Romania was represented by the Romanian Police, the Directorate for Combating Organized Crime and the Central Cybercrime Unit.
Sality has been operating since 2003 and has infected millions of computers, which were subsequently used to steal cryptocurrencies, conduct cyberattacks and send spam messages. At its peak, the botnet provided access to more than one million devices simultaneously, while more than 11 million IP addresses were associated with its infrastructure.
The operation relied on the “sinkholing” technique, through which communications from infected devices were redirected away from the criminals’ servers. The measure isolated the compromised computers and rendered the hackers’ command channel unusable. The action also received support from CrowdStrike, the Shadowserver Foundation, Eurojust and Europol.
As part of the operation, US authorities, including the FBI and DCIS, seized servers and domains in the United States. In Europe, partners in Bulgaria, Hungary and Romania took action against other domains associated with Sality. Romania was represented by the Romanian Police, the Directorate for Combating Organized Crime and the Central Cybercrime Unit.
Sality has been operating since 2003 and has infected millions of computers, which were subsequently used to steal cryptocurrencies, conduct cyberattacks and send spam messages. At its peak, the botnet provided access to more than one million devices simultaneously, while more than 11 million IP addresses were associated with its infrastructure.
The operation relied on the “sinkholing” technique, through which communications from infected devices were redirected away from the criminals’ servers. The measure isolated the compromised computers and rendered the hackers’ command channel unusable. The action also received support from CrowdStrike, the Shadowserver Foundation, Eurojust and Europol.
Sources
FBI laudă România, Ungaria și Bulgaria: împreună au lovit o rețea de hacking rusească / A fost distrusă o rețea malware cu peste 11 milioane de IP-uri infectate
Lovitură internațională împotriva hackerilor: Poliția Română, lăudată de SUA pentru implicată în neutralizarea rețelei Sality
România, în operațiunea FBI care a lovit o rețea de hacking suspectată că era operată din Rusia. Peste 11 milioane de IP-uri, legate de Sality
SUA, România, Bulgaria și Ungaria au neutralizat botnet-ul Sality, legat de Rusia. FBI laudă parteneriatul de lungă durată
Latest News
20:40
Irish Presidency to present new negotiating framework for the 2028–2034 EU budget on October 10
20:34
Donald Trump announces a $6.6 billion investment with Anduril, a company financed by a firm associated with his son
20:30
EU calls for rapid formation of authorities in Bosnia and Herzegovina and resumption of accession reforms
20:21
Commission closes two proceedings against France after opening at least 40% of hydropower capacity to EDF competitors
20:04
Romanian College of Physicians: The plague can be treated effectively if diagnosed and treated in time
See more news