International law enforcement agencies and private-sector partners have seized infrastructure linked to the Sality malware in a joint operation targeting the peer-to-peer (P2P) botnet.
The U.S. Department of Justice (DOJ), FBI, and DCIS seized Sality-linked domains in the United States. Law enforcement partners in Bulgaria, Hungary, and Romania seized additional domains hosted in Europe.
CrowdStrike’s Counter Adversary Operations team also dismantled Sality’s control channels through a P2P sinkhole operation that isolated infected machines. Investigators sinkholed the botnet’s known super peers, which form its communication backbone, to stop file packs and URL packs from spreading and to purge infected machines’ peer lists.
Sality has operated for more than two decades and has infected over 15,000 devices since at least 2003. CrowdStrike said the two Sality networks still active during the takedown were mainly used to distribute EggJagger malware in clipjacking attacks.
EggJagger monitors clipboard contents for cryptocurrency wallet addresses and silently replaces them with addresses controlled by the operator. Sality has also distributed malware linked to credential theft, spam distribution, proxy services, network exploitation, and distributed denial-of-service (DDoS) attacks.
CrowdStrike said Sality is no longer under the operator’s control following the disruption operation.
Comments
0No comments yet. Be the first to comment.