Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes

https://image.theregister.com/247072.jpg?imageId=247072&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683

23-year-old botnet down

International law enforcement agencies, working with CrowdStrike and Shadowserver Foundation, have disrupted Sality, a 23-year-old peer-to-peer botnet used to deliver malware to more than 15,000 machines worldwide.

The botnet has operated since 2003 and distributed all types of malicious code to victims, spanning credential theft, spam distribution, proxy services, network exploitation, and distributed denial-of-service (DDoS) attacks.

For the past eight years, Sality’s primary payload has been EggJagger, a tool that monitors clipboards for cryptocurrency wallet addresses, then silently replaces them with attacker-controlled addresses. When a victim copies a bitcoin or ethereum address to make a payment, the malware redirects funds into the criminals’ wallets.

CrowdStrike estimates Sality's operator stole at least $150,000 in cryptocurrency using EggJagger alone.

On Monday, CrowdStrike's Counter Adversary Operations team, working with international law enforcement agencies and industry partners, disrupted Sality by executing a peer-to-peer sinkhole operation.

This operation isolated infected machines, which...

Copyright of this story solely belongs to theregister.com. To see the full text click HERE

Read more