Sality Botnet Disrupted: $150,000 in Cryptocurrency Stolen Through EggJagger Malware
A significant cybersecurity operation has led to the disruption of the Sality botnet, which was active since 2003. The botnet had over 15,000 infected machines and was used primarily for delivering malware known as EggJagger.
EggJagger monitored cryptocurrency wallet addresses on devices and replaced them with addresses controlled by its operator, allowing the theft of funds from unsuspecting users. According to CrowdStrike, this mechanism resulted in at least $150,000 in stolen cryptocurrency over the past eight years.
The operation involved law enforcement agencies from the US, Bulgaria, Hungary, and Romania, who worked together to isolate infected machines and prevent further attacks. However, it's essential to note that the malware remains active on affected systems until it is removed, and users are advised to take remediation measures.