A botnet running for 23 years with over 15,000 endpoints has finally been shut down by law enforcement and Crowdstrike
- Crowdstrike and law enforcement disrupted Sality, a peer‑to‑peer botnet active since 2003
- Botnet spread malware and clipboard hijacker EggJagger, stealing $150K in cryptocurrency
- Operation sinkholed endpoints and removed payload URLs, coordinated with DOJ, FBI, Europol, and others
Security experts Crowdstrike, together with a handful of national and international law enforcement agencies, finally managed to disrupt Sality, a peer-to-peer botnet that operated unabated for more than two decades.
Sality first emerged in 2003. Unlike classic botnets which receive instructions and report back to a single, central entity, this botnet’s endpoints (some 15,000 of them) communicated among themselves, which made it more difficult to track and destroy.
Throughout its long history, Sality’s key feature was to deploy additional payloads to infected machines. The endpoints were being poisoned with a wide variety of different malwarethat facilitated credential theft, spam, proxy services, and distributed denial of service (DDoS) attacks. However, between...
Copyright of this story solely belongs to techradar.com. To see the full text click HERE