Sality Botnet Disruption Leaves Malware Remnant Threatening Crypto Payments
The Sality botnet's disruption on August 31 cut off its operator's ability to distribute new malicious software, but users of infected machines still need to remove installed malware. This includes a tool called EggJagger that swaps cryptocurrency addresses and can redirect payments.
CrowdStrike reported that the botnet enabled payload distribution to more than 33,000 infected machines worldwide. However, the number of users who lost cryptocurrency remains unspecified.
The Justice Department announced a multinational operation on September 1, following action taken by authorities in Bulgaria, Hungary, and Romania against Sality-linked domains.