Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Crime & Justice

International law enforcement and CrowdStrike cripple 23-year-old Sality botnet with sinkhole operation

Global police forces teamed with CrowdStrike to dismantle the Sality peer-to-peer botnet, isolating infected machines and halting its malicious activities.

A coalition of international law-enforcement agencies, the cybersecurity firm CrowdStrike, and the Shadowserver Foundation succeeded in disrupting the Sality botnet, a peer-to-peer network that has operated since 2003 and compromised more than 15,000 devices worldwide. The botnet’s primary payload, the EggJagger malware, hijacked cryptocurrency wallet addresses to divert payments, generating at least $150,000 in stolen funds, according to CrowdStrike estimates.

On Monday, CrowdStrike’s Counter Adversary Operations team launched a peer-to-peer sinkhole campaign that systematically removed authentic super-peers from each infected host’s peer list and inserted sinkhole entries, effectively isolating the bots and cutting off command and control. The U.S. Justice Department, FBI and the Department of Defense’s Defense Criminal Investigative Service seized Sality-linked domains in the United States, while authorities in Bulgaria, Hungary and Romania acted against additional European domains. The Shadowserver Foundation is now working with internet service providers and CSIRTs to locate infected machines and help victims remediate the threat.

Why it matters

Disrupting Sality removes a long-standing malware platform that stole crypto funds and enabled spam, DDoS and other attacks.

In this story

Sality botnetpeer-to-peer sinkholeEggJaggercryptocurrency theftCrowdStrikeinternational law enforcement
Get the beta ↗