US Officials Dismantle Decades-Old Sality Malware Network
The US Department of Justice (DOJ) announced an operation targeting the Sality malware ecosystem, which has been used to steal cryptocurrency and carry out cyberattacks for over two decades. The operation involved cooperation with cybersecurity company CrowdStrike and international partners from Bulgaria, Hungary, and Romania.
The DOJ said that the Sality botnet and malware infrastructure were disrupted through a coordinated international takedown. CrowdStrike reported that clipboard-based 'clipjacking' was used to replace cryptocurrency addresses with attacker-controlled ones.
The entities behind Sality stole at least 12.1 million rubles, or about $150,000, over the prior eight years. The malware operators used EggJagger, a clipjacking tool that monitors a victim's clipboard for cryptocurrency wallet addresses and then silently swaps them for addresses controlled by the attacker.