International law enforcement agencies and private partners seized Sality-linked infrastructure in the U.S. and Europe, while CrowdStrike helped dismantle the botnet’s peer-to-peer control channels. The operation disrupted more than two decades of activity tied to SALTY SPIDER and its use of Sality to spread EggJagger payloads in clipjacking attacks. #Sality #SALTYSPIDER #EggJagger #CrowdStrike #DOJ #FBI #DCIS
Keypoints
- Law enforcement seized Sality-linked domains in the United States and Europe.
- CrowdStrike and partners sinkholed the botnet’s super peers to break its communication network.
- Sality has been active since at least 2003 and infected over 15,000 devices.
- SALTY SPIDER is believed to operate from the Republic of Bashkortostan in Russia.
- The botnet was mainly used to distribute EggJagger in clipjacking attacks targeting cryptocurrency wallets.