The United States, Bulgaria, Hungary and Romania took part in an international operation to neutralize the Sality botnet, a malware infrastructure associated with Russia and used for cybercrime. The action, announced by the US Department of Justice and Europol, targeted servers and domains used to control the network, as well as to distribute the malicious software.
As part of the operation, US authorities, including the FBI and DCIS, seized servers and domains in the United States. In Europe, partners in Bulgaria, Hungary and Romania took action against other domains associated with Sality. Romania was represented by the Romanian Police, the Directorate for Combating Organized Crime and the Central Cybercrime Unit.
Sality has been operating since 2003 and has infected millions of computers, which were subsequently used to steal cryptocurrencies, conduct cyberattacks and send spam messages. At its peak, the botnet provided access to more than one million devices simultaneously, while more than 11 million IP addresses were associated with its infrastructure.
The operation relied on the “sinkholing” technique, through which communications from infected devices were redirected away from the criminals’ servers. The measure isolated the compromised computers and rendered the hackers’ command channel unusable. The action also received support from CrowdStrike, the Shadowserver Foundation, Eurojust and Europol.
As part of the operation, US authorities, including the FBI and DCIS, seized servers and domains in the United States. In Europe, partners in Bulgaria, Hungary and Romania took action against other domains associated with Sality. Romania was represented by the Romanian Police, the Directorate for Combating Organized Crime and the Central Cybercrime Unit.
Sality has been operating since 2003 and has infected millions of computers, which were subsequently used to steal cryptocurrencies, conduct cyberattacks and send spam messages. At its peak, the botnet provided access to more than one million devices simultaneously, while more than 11 million IP addresses were associated with its infrastructure.
The operation relied on the “sinkholing” technique, through which communications from infected devices were redirected away from the criminals’ servers. The measure isolated the compromised computers and rendered the hackers’ command channel unusable. The action also received support from CrowdStrike, the Shadowserver Foundation, Eurojust and Europol.
Sources
FBI laudă România, Ungaria și Bulgaria: împreună au lovit o rețea de hacking rusească / A fost distrusă o rețea malware cu peste 11 milioane de IP-uri infectate
Lovitură internațională împotriva hackerilor: Poliția Română, lăudată de SUA pentru implicată în neutralizarea rețelei Sality
România, în operațiunea FBI care a lovit o rețea de hacking suspectată că era operată din Rusia. Peste 11 milioane de IP-uri, legate de Sality
SUA, România, Bulgaria și Ungaria au neutralizat botnet-ul Sality, legat de Rusia. FBI laudă parteneriatul de lungă durată
Latest News
13:58
Romanian customs officers seized more than one million cigarettes from Moldova / The smuggled goods are worth more than 3.5 million lei
13:51
DNA opened a criminal case after footage showed bags and goods ending up in the car of the head of the Labour Inspectorate
13:44
USA: Charlie Kirk’s family accuses Utah Valley University and state authorities of inadequate security measures before the attack
13:37
The AEP proposes that Parliament appoint its entire leadership, while obstructing inspections would be punishable by fines of up to 20,000 lei
13:30
Bucharest Gendarmerie: 6 people detained and 24 sanctions following the farmers' protest in Victory Square
See more news