Sality Botnet Disrupted, Over 15,000 Infected Machines Isolated
CrowdStrike and the U.S. Department of Justice have disrupted the Sality botnet, isolating over 15,000 infected machines used in cryptocurrency theft.
The Sality botnet, active since 2003, primarily delivered EggJagger, a tool that monitored copied cryptocurrency wallet addresses and replaced them with addresses controlled by its operator.
This mechanism allowed the malware to redirect funds from intended recipients during payment workflows. According to CrowdStrike, EggJagger alone was responsible for at least $150,000 in stolen cryptocurrency over the past eight years.
The operation targeted a damaging weakness in cryptocurrency payment workflows and involved manipulating peer lists by removing legitimate peers and inserting CrowdStrike-controlled sinkholes, effectively isolating infected machines from the operator's control.