The operation, announced Monday, targeted the 23-year-old Sality botnet, which has been used to distribute a variety of malicious payloads including credential theft, spam distribution, proxy services, network exploitation, and distributed denial-of-service attacks. For the past eight years, Sality’s primary payload has been EggJagger, a tool that monitors clipboards for cryptocurrency wallet addresses and silently replaces them with attacker-controlled addresses, redirecting payments intended for victims to the criminals.
CrowdStrike's Counter Adversary Operations team, in a technical writeup, described the disruption as a peer-to-peer sinkhole operation. Each Sality bot maintains a list of known super peers — publicly reachable infected machines that form the network’s backbone. Bots check every 40 minutes whether their peers are still online; unresponsive peers are purged. The counterattack removed legitimate super peers from each bot's peer list, gradually isolating infected machines, and inserted purpose-built sinkhole entries that gave investigators visibility into the network and helped identify victims.
In addition to the technical takedown, the US Justice Department, FBI, and Department of Defense Office of Inspector General's Defense Criminal Investigative Service seized Sality-linked domains in the United States. Meanwhile, law enforcement in Bulgaria, Hungary, and Romania took similar action against Sality-linked domains hosted in Europe. The Shadowserver Foundation is now working with internet service providers and Computer Security Incident Response Teams to identify infections and notify victims.