International Operation Disrupts 23-Year-Old Sality Botnet, Targeting Cryptocurrency Theft

CrowdStrike, law enforcement agencies sinkhole peer-to-peer network used to steal at least $150,000 in crypto

edit
By LineZotpaper
Published
Read Time2 min
International law enforcement agencies, working with CrowdStrike and the Shadowserver Foundation, have disrupted the Sality botnet — a peer-to-peer malware network operating since 2003 that infected more than 15,000 machines worldwide and stole at least $150,000 in cryptocurrency through clipboard-hijacking malware.

The operation, announced Monday, targeted the 23-year-old Sality botnet, which has been used to distribute a variety of malicious payloads including credential theft, spam distribution, proxy services, network exploitation, and distributed denial-of-service attacks. For the past eight years, Sality’s primary payload has been EggJagger, a tool that monitors clipboards for cryptocurrency wallet addresses and silently replaces them with attacker-controlled addresses, redirecting payments intended for victims to the criminals.

CrowdStrike's Counter Adversary Operations team, in a technical writeup, described the disruption as a peer-to-peer sinkhole operation. Each Sality bot maintains a list of known super peers — publicly reachable infected machines that form the network’s backbone. Bots check every 40 minutes whether their peers are still online; unresponsive peers are purged. The counterattack removed legitimate super peers from each bot's peer list, gradually isolating infected machines, and inserted purpose-built sinkhole entries that gave investigators visibility into the network and helped identify victims.

In addition to the technical takedown, the US Justice Department, FBI, and Department of Defense Office of Inspector General's Defense Criminal Investigative Service seized Sality-linked domains in the United States. Meanwhile, law enforcement in Bulgaria, Hungary, and Romania took similar action against Sality-linked domains hosted in Europe. The Shadowserver Foundation is now working with internet service providers and Computer Security Incident Response Teams to identify infections and notify victims.

§

Analysis

Why This Matters

  • The takedown removes a long-running botnet infrastructure that has been a vector for multiple types of cybercrime, including cryptocurrency theft, for nearly a quarter-century.
  • Victims whose machines remain infected are now isolated and unable to receive new instructions, but may still need remediation to remove the malware.
  • The operation demonstrates that law enforcement and industry can collaborate to disrupt peer-to-peer botnets, which are notoriously difficult to takedown due to their distributed nature.

Background

Sality is one of the oldest known peer-to-peer botnets, first appearing in 2003. Unlike botnets that rely on central command-and-control servers, Sality uses a decentralized peer-to-peer structure where infected machines communicate with each other directly, making it more resilient to traditional takedown methods. Over the years, it has been used to distribute a wide range of malware. The recent operation employed a sinkhole technique that exploits the botnet's own peer-list purging mechanism to gradually isolate infected machines.

Key Perspectives

Law enforcement agencies (US, Bulgaria, Hungary, Romania): Their domain seizures and coordination with industry partners aim to dismantle the criminal infrastructure and deter future botnet operations. CrowdStrike and Shadowserver Foundation: Their technical expertise enabled the sinkhole operation and victim notification, highlighting the role of private cybersecurity firms in disrupting cybercrime. Victims and security researchers: Those whose machines remain infected may still be at risk from residual malware, and long-term monitoring will be needed to ensure the botnet does not re-establish itself.

What to Watch

  • Whether victims successfully remediate their machines, and how many remain infected after the sinkhole operation.
  • Potential resurgence of the botnet if the operators regain control or modify their peer-list architecture in response.
  • Future law enforcement actions targeting other long-lived P2P botnets using similar sinkhole techniques.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.