A botnet running for 23 years with over 15,000 endpoints has finally been shut down by law enforcement and Crowdstrike
Crowdstrike and law enforcement disrupted Sality , a peer‑to‑peer botnet active since 2003 Botnet spread malware and clipboard hijacker EggJagger , stealing $150K in cryptocurrency Operation sinkholed endpoints and removed payload URLs, coordinated with DOJ, FBI, Europol, and others Security experts Crowdstrike, together with a handful of national and international law enforcement agencies, finally managed to disrupt Sality, a peer-to-peer botnet that operated unabated for more than two decades.
Sality first emerged in 2003.
Unlike classic botnets which receive instructions and report back to a single, central entity, this botnet’s endpoints (some 15,000 of them) communicated among themselves, which made it more difficult to track and destroy.
Throughout its long history, Sality’s key feature was to deploy additional payloads to infected machines.
The endpoints were being poisoned with a wide variety of different malware that facilitated credential theft, spam, proxy services, and distributed denial of service (DDoS) attacks.
However, between 2018 and today, Sality was primarily used to deploy EggJagger, a clipboard hijacking tool seen in cryptocurrency theft.
Sinkholing the botnet Cryptocurrency wallet addresses are a long string of random characters, which are almost impossible, and definitely impractical, to remember by heart.
Instead, when users want to send their money, they simply copy and paste the recipient’s wallet address into their own.
EggJagger monitors this behavior, and when it spots something resembling a wallet address being copied, it replaces the string in the clipboard.
Thus, when the victim hits “paste”, they end up adding the attacker’s wallet address instead.
According to Crowdstrike, from this malware alone, Sality’s operators raked in more than $150,000.
The researchers disrupted the botnet by sinkholing the endpoints.
They first added a few of their own devices into the botnet and whenever others tried to communicate with them, the researchers would purge their peers list, essentially blinding them.
Crowdstrike also coordinated with international law enforcement to take down the URLs that were hosting the botnet’s payloads.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.