Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes
International law enforcement agencies, working alongside CrowdStrike and the Shadowserver Foundation, have disrupted Sality, a peer-to-peer botnet that has operated since 2003 and infected more than 15,000 machines worldwide. The takedown matters because Sality had become a long-running vehicle for varied cybercrime, including credential theft, spam distribution, proxy abuse, network exploitation and DDoS attacks, and had more recently been used to quietly redirect victims' cryptocurrency payments.
For the past eight years, Sality's main payload was EggJagger, malware that monitored clipboards for bitcoin and ethereum wallet addresses and silently swapped them for attacker-controlled ones, netting criminals at least $150,000 according to CrowdStrike. The disruption operation worked by targeting each bot's list of "super peers", which are checked every 40 minutes, purging legitimate peers and inserting sinkhole entries to isolate infected machines and cut off communication with operators. US authorities, including the Justice Department, FBI and Defense Criminal Investigative Service, seized related domains, while Bulgaria, Hungary and Romania acted against European infrastructure, with Shadowserver now helping ISPs and CSIRTs identify and remediate infections.
- 23-year-old Sality botnet disrupted by police and CrowdStrike
- Malware EggJagger hijacked crypto payments, stealing over $150,000
- Sinkhole operation poisoned peer lists to isolate 15,000+ infected machines