Wednesday, 2 September 2026 SourcesAbout🌓
🇬🇧 UK ▾
BREAKING
Technology

Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes

The Register ·
Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes

International law enforcement agencies, working with CrowdStrike and Shadowserver Foundation, have disrupted Sality, a 23-year-old peer-to-peer botnet used to deliver malware to more than 15,000 machines worldwide.

The botnet has operated since 2003 and distributed all types of malicious code to victims, spanning credential theft, spam distribution, proxy services, network exploitation, and distributed denial-of-service (DDoS) attacks.

For the past eight years, Sality’s primary payload has been EggJagger, a tool that monitors clipboards for cryptocurrency wallet addresses, then silently replaces them with attacker-controlled addresses.

When a victim copies a bitcoin or ethereum address to make a payment, the malware redirects funds into the criminals’ wallets.

CrowdStrike estimates Sality's operator stole at least $150,000 in cryptocurrency using EggJagger alone.

On Monday, CrowdStrike's Counter Adversary Operations team, working with international law enforcement agencies and industry partners, disrupted Sality by executing a peer-to-peer sinkhole operation.

This operation isolated infected machines, which broke the criminal operator’s ability to communicate with devices on its network.

Once isolated, the bots can no longer receive payload download instructions or direct payload transfers, effectively breaking the botnet.

“In practice, the operation targeted the data structure at the heart of every bot's network awareness: its peer list,” CrowdStrike Counter Adversary Operations team said in a technical writeup about the takedown.

Each Sality bot maintains a list of known super peers – publicly reachable infected machines that form the backbone of the P2P network.

Every 40 minutes, the bots check to see if their peers are still online.

Peers that fail to respond are purged from the network.

The counterattack took advantage of this by removing legitimate super peers in each bot’s peer list, continually isolating more infected machines in the network, and inserting purpose-built sinkhole entries into peer lists.

That approach gave police and cyber operatives visibility into the operation’s progress and helped them notify victims.

Read the full article on The Register ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.

More from The Register

See all ›

More in Technology

See all ›