Sality Botnet Disrupted, Operator Cut Off From Infected Machines
The US Justice Department has announced an international operation to disrupt the Sality botnet, used for cryptocurrency theft and other cyberattacks. The operation involved authorities in Bulgaria, Hungary, and Romania, alongside CrowdStrike and the Shadowserver Foundation.
Sality's operator had been using a clipjacking tool called EggJagger since 2003 to steal at least $150,000 in cryptocurrency over eight years. This tool monitored device clipboards for wallet addresses and replaced them with controlled addresses, allowing payments to be redirected.
The disruption severed the operator's communication with compromised machines, isolating over 15,000 infected computers from receiving new payload instructions or direct payload transfers.