Sality Botnet Dismantled After Stealing Over $150,000 in Cryptocurrency
The Sality botnet, active since 2003, has been dismantled after eight years of targeting cryptocurrency payments. The malware network was used to steal Bitcoin and Ethereum through a tool called EggJagger, which monitored victims' clipboards and replaced copied wallet addresses with ones controlled by the attackers.
CrowdStrike and the U.S. Department of Justice isolated over 15,000 infected machines worldwide after disrupting the botnet's peer-to-peer infrastructure. The operation targeted Sality's cryptocurrency-stealing payload, EggJagger, which generated at least $150,000 in stolen cryptocurrency.
The stolen funds were not spent and instead helped investigators understand the scale of the operation. The decentralized structure of Sality made it difficult for authorities to simply seize a server and shut down the operation. Instead, CrowdStrike infiltrated the botnet's communication system and removed legitimate peers from infected machines' address lists.