Back to feed

Sality botnet infrastructure dismantled in joint global takedown

2 min
Sality botnet infrastructure dismantled in joint global takedown

This digest was compiled by AI from multiple sources — links to the originals are below.

International law enforcement and private partners seized Sality malware infrastructure in a joint action targeting the peer-to-peer botnet. The operation involved the U.S. Department of Justice, FBI, and DCIS, along with partners in Bulgaria, Hungary, and Romania. CrowdStrike's Counter Adversary Operations team also dismantled the botnet's control channels through a peer-to-peer sinkhole operation.

Key Facts

  • The Sality botnet has been active for more than two decades and has infected over 15,000 devices since at least 2003.
  • The U.S. Department of Justice, FBI, and DCIS seized Sality-linked domains in the United States, while partners in Bulgaria, Hungary, and Romania seized additional domains in Europe.
  • CrowdStrike tracks the criminal group behind Sality as SALTY SPIDER, likely operating out of the Republic of Bashkortostan in Russia.
  • For the past eight years, the primary payload distributed by Sality has been EggJagger, a clipjacking tool that replaces cryptocurrency wallet addresses.
  • The P2P botnet was disrupted by sinkholing Sality's list of known super peers to block file packs and URL packs from propagating.

Operation Details

The U.S. Department of Justice (DOJ), FBI, and DCIS seized Sality-linked domains in the United States. Law enforcement partners in Bulgaria, Hungary, and Romania seized additional Sality-linked domains hosted in Europe. CrowdStrike's Counter Adversary Operations team, in collaboration with international law enforcement and private industry partners, dismantled the botnet's control channels in a peer-to-peer sinkhole operation that isolated infected machines. The P2P botnet was disrupted by sinkholing Sality's list of known super peers, which form its communication backbone, to block file packs and URL packs from propagating and purging infected machines' peer lists.

Malware History and Impact

The Sality botnet has been active for more than two decades and has infected over 15,000 devices with malware since at least 2003, when it first surfaced. CrowdStrike says Sality is controlled by a criminal group it tracks as SALTY SPIDER, which is likely operating out of the Republic of Bashkortostan in Russia. Throughout its history, Sality distributed a wide variety of distinct malware families spanning credential theft, spam distribution, proxy services, network exploitation, and distributed denial-of-service (DDoS) attacks. For the past eight years, the primary payload has been EggJagger, a clipjacking tool that monitors the clipboard for cryptocurrency wallet addresses and silently replaces them with addresses controlled by the operator.

Recent Takedown Context

According to CrowdStrike, the two separate Sality botnet networks that were still active when the takedown took place this week were mainly used to push EggJagger malware payloads in clipjacking attacks. After more than two decades of continuous operation, CrowdStrike, together with international law enforcement and industry partners, conducted a successful disruption operation against the Sality botnet, which is now no longer under the operator's control. In March, American and European authorities, along with private partners, disrupted the SocksEscort cybercrime proxy network and took down Command and Control (C2) infrastructure used by the Aisuru, KimWolf, JackSkid, and Mossad botnets.

1 source

Time · lag behind first