A botnet running for 23 years with over 15,000 endpoints has finally been shut down by law enforcement and Crowdstrike

Wait 5 sec.

Crowdstrike and law enforcement disrupted Sality, a peer‑to‑peer botnet active since 2003Botnet spread malware and clipboard hijacker EggJagger, stealing $150K in cryptocurrencyOperation sinkholed endpoints and removed payload URLs, coordinated with DOJ, FBI, Europol, and othersSecurity experts Crowdstrike, together with a handful of national and international law enforcement agencies, finally managed to disrupt Sality, a peer-to-peer botnet that operated unabated for more than two decades. Sality first emerged in 2003. Unlike classic botnets which receive instructions and report back to a single, central entity, this botnet’s endpoints (some 15,000 of them) communicated among themselves, which made it more difficult to track and destroy.Throughout its long history, Sality’s key feature was to deploy additional payloads to infected machines. The endpoints were being poisoned with a wide variety of different malware that facilitated credential theft, spam, proxy services, and distributed denial of service (DDoS) attacks. However, between 2018 and today, Sality was primarily used to deploy EggJagger, a clipboard hijacking tool seen in cryptocurrency theft.Sinkholing the botnetCryptocurrency wallet addresses are a long string of random characters, which are almost impossible, and definitely impractical, to remember by heart. Instead, when users want to send their money, they simply copy and paste the recipient’s wallet address into their own. EggJagger monitors this behavior, and when it spots something resembling a wallet address being copied, it replaces the string in the clipboard. Thus, when the victim hits “paste”, they end up adding the attacker’s wallet address instead. According to Crowdstrike, from this malware alone, Sality’s operators raked in more than $150,000. The researchers disrupted the botnet by sinkholing the endpoints. They first added a few of their own devices into the botnet and whenever others tried to communicate with them, the researchers would purge their peers list, essentially blinding them.Crowdstrike also coordinated with international law enforcement to take down the URLs that were hosting the botnet’s payloads. “Disrupting Sality’s ability to download these files ensures that bots still carrying active URL packs cannot retrieve new payloads during the transition period,” they explained.The operation was carried out in partnership with the US Department of Justice (DOJ), the Federal Bureau of Investigation (FBI), the Department of Defense Office of Inspector General’s Defense Criminal Investigative Service (DCIS), and the Shadowserver Foundation, with support from Europol, Eurojust, and law enforcement agencies in Bulgaria, Hungary, and Romania. “We also acknowledge additional unnamed partners whose contributions were essential to the success of this operation,” Crowdstrike concluded.Via The Register