CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5871

As cited

Copy frozen at (site build).

threat intel

Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes

International law enforcement agencies, CrowdStrike, and the Shadowserver Foundation disrupted Sality, a 23-year-old peer-to-peer botnet infecting more than 15,000 machines globally. The operation isolated infected devices by manipulating each bot's peer list, preventing the attacker from delivering malicious payloads and communicating with compromised machines. Over eight years, Sality primarily distributed EggJagger, clipboard-monitoring malware that redirected cryptocurrency transfers to attacker-controlled wallets, netting at least $150,000 in stolen funds.

Why it matters: Organizations and individuals running unpatched systems or lacking endpoint detection need to verify whether their devices were among the 15,000 infected machines and work with their ISP and incident response team to confirm remediation.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes

International law enforcement agencies, CrowdStrike, and the Shadowserver Foundation disrupted Sality, a 23-year-old peer-to-peer botnet infecting more than 15,000 machines globally. The operation isolated infected devices by manipulating each bot's peer list, preventing the attacker from delivering malicious payloads and communicating with compromised machines. Over eight years, Sality primarily distributed EggJagger, clipboard-monitoring malware that redirected cryptocurrency transfers to attacker-controlled wallets, netting at least $150,000 in stolen funds.

Why it matters: Organizations and individuals running unpatched systems or lacking endpoint detection need to verify whether their devices were among the 15,000 infected machines and work with their ISP and incident response team to confirm remediation.

VendorsCrowdStrike
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary