Security company Crowdstrike and national and international law enforcement agencies have disrupted Sality, a peer-to-peer botnet that operated for more than two decades.
Sality first emerged in 2003 and had about 15,000 endpoints. Unlike botnets controlled by a single central entity, its endpoints communicated among themselves, making the network harder to track and dismantle.
Over its history, Sality delivered additional malware payloads that enabled credential theft, spam, proxy services, and distributed denial of service (DDoS) attacks. From 2018 onward, it was primarily used to deploy EggJagger, a clipboard hijacking tool linked to cryptocurrency theft.
EggJagger monitored copied text resembling a cryptocurrency wallet address and replaced it with an attacker-controlled address. Crowdstrike said Sality’s operators made more than $150,000 from this malware.
Researchers disrupted the botnet by sinkholing endpoints. They added their own devices to the network and purged peer lists when other endpoints connected, effectively blinding them. Crowdstrike also coordinated the takedown of URLs hosting Sality’s payloads.
The operation involved the US Department of Justice (DOJ), the Federal Bureau of Investigation (FBI), the Department of Defense Office of Inspector General’s Defense Criminal Investigative Service (DCIS), and the Shadowserver Foundation, with support from Europol, Eurojust, and agencies in Bulgaria, Hungary, and Romania.
Comments
0No comments yet. Be the first to comment.