Sality botnet infrastructure dismantled in joint global takedown

Sality botnet infrastructure dismantled in joint global takedown
International law enforcement agencies and private partners seized Sality-linked infrastructure in the U.S. and Europe, while CrowdStrike helped dismantle the botnet’s peer-to-peer control channels. The operation disrupted more than two decades of activity tied to SALTY SPIDER and its use of Sality to spread EggJagger payloads in clipjacking attacks. #Sality #SALTYSPIDER #EggJagger #CrowdStrike #DOJ #FBI #DCIS

Keypoints

  • Law enforcement seized Sality-linked domains in the United States and Europe.
  • CrowdStrike and partners sinkholed the botnet’s super peers to break its communication network.
  • Sality has been active since at least 2003 and infected over 15,000 devices.
  • SALTY SPIDER is believed to operate from the Republic of Bashkortostan in Russia.
  • The botnet was mainly used to distribute EggJagger in clipjacking attacks targeting cryptocurrency wallets.

Read More: https://www.bleepingcomputer.com/news/security/sality-botnet-infrastructure-dismantled-in-joint-global-takedown/