Forgotten Dairies
Sality Fell, But Cyber Justice Remains Offline -By Fransiscus Nanga Roka
It is a big win for Silas that silenced Sality. The world has shut down the weapon as long as its victims are wiped clean, profits recovered and operator jailed. But the gunman is free.
So the end, when it came for Sality after outliving presidents, operating systems, and generations of cybersecurity technology was banishment rather than defeat.
US authorities orchestrated a multinational effort with Bulgaria, Hungary and Romania, backed by Europol, Eurojust, CrowdStrike and the Shadowserver Foundation to shut down one of the longest-running botnets in the world on Aug. 31, 2023. Authorities in the United States, including the Justice Department, FBI and Defense Criminal Investigative Service, seized 63 domains linked to Sality as European authorities worked against infrastructure within their borders.
Sality is first spotted in 2003, It used to infect Windows executable files and spread over network shares, removable drives and in file-sharing systems. While malware needs new phishing campaigns, it could reproduce itself from infected files. Using a decentralized peer-to-peer structure, it removed the single-server of command which authorities typically take control of.
Sality was said to once allow up to one million machines under the direct control of its operators with over 11 million unique IP addresses having been used in association with its infrastructure. Prior to the operation, CrowdStrike found over 33,000 infected machines, but other counts were lower an example of how different measures arise from differently dynamic networks without necessarily contradicting reality.
What did Sality do? It provided a flexible cybercrime arsenal for credential theft, spam, proxy services, network exploitation, and distributed-denial-of-service attacks. Since around 2018, its main cargo was EggJagger, a clipboard hijacker that recognized Bitcoin and Ethereum addresses copied to the clipboard and subsequently unobtrusively exchanged them for wallets in the assailants control. According to CrowdStrike estimates, the operation took over $150000 in cryptocurrency not including from additional payloads.
How was a seizure-resilient infrastructure architecture defanged?
The investigators were able to leverage Sality’s own architecture of trust against it. Every 40 minutes, the infected devices re-evaluated their lists of public-facing super peers. Because the protocol did not include authentication, cryptographic identity and an allowlist, defenders impersonating legitimate network participants could have entered the system. They nullified criminal super peers, added artificial sinkholes and rerouted infected hosts away from the operator. At the same time, authorities took down the domains used to host additional payloads.
Technically, it was surgical. It was politically dramatic: CrowdStrike initiated the disruption when demonstrating it live at its Day Zero summit in Las Vegas. However, governments shouldn not be celebrating victory from a podium.
The unknown perpetrator has yet to be identified or apprehended. While sinkholing can help prevent infected computers from receiving new commands, it does nothing to disinfect the compromised files, recover stolen credentials or compensate victims. CrowdStrike itself cautions that you still have to eliminate current malware.
Cyber containment using a botnet takedown without attribution, prosecution and remediation is not cyber justice.
Three reforms are essential.
Foremost, sinkholing should be governed by the aforementioned legal authorities (with appropriate judicial safeguards) and territorial limits. Access to thousands of foreign computers przysiege implemented by private means may be defensive, public-private cyber power does not work through secret legality.
Second, sinkhole telemetric data must be transformed into rapid victim notification released by Shadowserver, national incident-response teams and then into removal tools without any charge provided for the victims along with remediation reports that are measurable.
Third, prosecutors should trace the money. Cryptocurrency exchanges are to keep track of wallet histories, freeze traceable proceEs and commit to acting in concert on confiscation and victim reimbursement. Create and pursue disclosures of evidence connecting suspects to the crimes, pressing Russia, formally if necessary, to preserve such material (where it has been possible for Russia to destroy or tamper with evidence), and press them into identifying such individuals; while anybody not cooperating should be the target of an ambitious regime (backed by published attribution evidence) involving financial asset freezes and EU travel bans.
Third, governments must create an ongoing multinational framework for P2P botnet disruption, including harmonised evidentiary standards; emergency judicial orders; cross-border data rules; and regimes for independent post-operation audits.
It is a big win for Silas that silenced Sality. The world has shut down the weapon as long as its victims are wiped clean, profits recovered and operator jailed. But the gunman is free.
Fransiscus Nanga Roka
Faculty of Law University 17 August 1945 Surabaya and Managing Partner Law Firm Victorious Indonesia
