CrowdStrike Dismantles Sality Crypto Botnet in US Operation
CrowdStrike has successfully dismantled the Sality crypto botnet in collaboration with US authorities. The botnet, which originated from Russia, was notorious for spreading through USB drives and operating as a decentralized peer-to-peer network.
This allowed infected computers to keep the botnet alive even after the initial infection. CrowdStrike identified a weakness in the system: every 40 minutes, infected devices would check if their known peers were still online. By exploiting this process, they managed to cut off over 15,000 machines from the network.
It's estimated that Sality stole at least $150,000 worth of crypto, with a peak value of up to $1.35 million during last year's surge in cryptocurrency prices.