In a coordinated international action, law enforcement agencies from the United States, Bulgaria, Hungary, and Romania, along with private industry partners, have targeted the Sality botnet. The U.S. Department of Justice (DOJ), FBI, and DCIS seized Sality-linked domains in the United States, while counterparts in Europe took down additional domains.
CrowdStrike's Counter Adversary Operations team played a key role by conducting a peer-to-peer sinkhole operation, isolating infected machines and blocking the botnet's control channels. According to the DOJ, the Sality botnet is a network of computers infected with the Sality malware and controlled by a single operator. CrowdStrike tracks the criminal group behind Sality as SALTY SPIDER, which is likely operating out of the Republic of Bashkortostan in Russia.
The takedown specifically targeted two Sality botnet networks that were still active. CrowdStrike stated that these networks were primarily used to push EggJagger malware payloads in clipjacking attacks. EggJagger monitors the clipboard for cryptocurrency wallet addresses and silently replaces them with addresses controlled by the operator. Over its long history, Sality has also been used for credential theft, spam distribution, proxy services, network exploitation, and distributed denial-of-service (DDoS) attacks.
The disruption was achieved by sinkholing Sality's list of known super peers, which form the botnet's communication backbone. This blocked file packs and URL packs from propagating and purged the peer lists of infected machines. CrowdStrike confirmed that the botnet is now no longer under the operator's control.