Although it has in recent years been overshadowed by more disruptive ransom-seeking cybercriminals, Sality, first spotted in 2003, remains one of the internet’s longest-running cybercriminal enterprises.
Sality's peer-to-peer architecture meant it could receive commands through a diffuse network of compromised machines, making it particularly resistant to law enforcement action.
But CrowdStrike said in a blog post published on Tuesday that it turned that strength against Sality by seeding the network with bogus information that tricked the botnet's components into cutting themselves off from their creator.
CrowdStrike researcher Tillmann Werner said that reverse-engineering the botnet's structure, finding weak points and building the infrastructure needed to knock it down had required painstaking work.
"This was the most complex botnet takeover we have ever done," Werner told Reuters. "This was built to be resilient. It was built to survive takedown or takeover. I think that's the reason it's been around for so long."
David Watson, director of nonprofit security group The Shadowserver Foundation, which was also involved in the takedown, said Sality was "quite old-school" but could still be dangerous.
“It's still a vector into a lot of organizations,” Watson said.
He said the next step would be to see what, if anything, Sality's creator, who has yet to be publicly identified, did to regain control of or re-create the botnet.
“What does he do?” Watson said. “Does he fight back?”