Sality botnet with 15,000 endpoints disrupted after 23 years
Sality botnet, running since 2003 with 15,000 endpoints, disrupted by Crowdstrike and law enforcement.
According to TechRadar, Sality first emerged in 2003. Unlike traditional botnets that rely on a central command server, Sality's endpoints communicated with each other in a peer-to-peer network, making it harder to track and dismantle. At its peak, the botnet comprised about 15,000 endpoints.
Over time, Sality delivered various payloads for credential theft, spam, proxy services, and DDoS attacks. Since 2018, it primarily deployed EggJagger, a clipboard hijacker used in cryptocurrency theft.
EggJagger works by monitoring clipboard activity. When a user copies a cryptocurrency wallet address, the malware replaces it with the attacker's address, causing the victim to send funds to the wrong recipient. According to Crowdstrike, Sality's operators earned more than $150,000 from this scheme.
To disrupt the botnet, Crowdstrike used a sinkholing technique. The researchers inserted their own devices into the network, and when other endpoints communicated with them, they purged the peer lists, effectively blinding the bots. The company also coordinated with international law enforcement to remove the URLs hosting the botnet's payloads.
The operation involved the US Department of Justice (DOJ), the Federal Bureau of Investigation (FBI), the Department of Defense Office of Inspector General's Defense Criminal Investigative Service (DCIS), and the Shadowserver Foundation, with support from Europol, Eurojust, and law enforcement agencies in Bulgaria, Hungary, and Romania. Crowdstrike acknowledged additional unnamed partners, according to the report.