Sality Botnet Finally Dismantled After Eight Years of Crypto Heists
The Sality botnet, which has been operating since 2003, has finally been dismantled by the Justice Department and CrowdStrike. The malware's primary payload for the past eight years was EggJagger, a clipjacking tool that monitored a victim's clipboard for cryptocurrency wallet addresses and replaced them with the operator's own.
CrowdStrike estimates that the operator stole at least $150,000 through this method alone, and that the unspent holdings later peaked at around $4 million in a Western capital. The botnet had no central server to seize, instead communicating directly between infected machines, which spread by attaching themselves to executable files.
The operation to take down Sality involved actions in multiple countries, including the US, Bulgaria, Hungary, and Romania, as well as collaboration with private industry partners CrowdStrike and the Justice Department. Over 15,000 infected machines worldwide were isolated through the use of sinkholes.