Global Law Enforcement Operation Dismantles Two-Decade-Old Sality Botnet
International law enforcement agencies and private partners have seized the infrastructure of the Sality malware in a joint global takedown. The operation is supported by Europol and Eurojust, while the U.S. Department of Justice, FBI, and DCIS seize Sality-linked domains in the United States. Authorities in Bulgaria, Hungary, and Romania seize additional Sality-linked domains hosted in Europe.
CrowdStrike's Counter Adversary Operations team works alongside law enforcement and industry partners to dismantle the botnet's control channels in a peer-to-peer sinkhole operation that isolates infected machines. The Sality botnet has been active for more than two decades and has infected over 15,000 devices since at least 2003. CrowdStrike tracks the operators as SALTY SPIDER, a criminal group likely operating out of the Republic of Bashkortostan in Russia.
Throughout its history, Sality distributes a wide variety of malware families covering credential theft, spam distribution, proxy services, network exploitation, and DDoS attacks. For the past eight years, its primary payload is EggJagger, a clipjacking tool that monitors the clipboard for cryptocurrency wallet addresses and silently swaps them with attacker-controlled addresses. The takedown works by sinkholing Sality's known super peers, blocking payload transfers from propagating, and purging infected machines' peer lists.