CrowdStrike and police disrupt 23-year-old Sality botnet

CrowdStrike and police disrupt 23-year-old Sality botnet

International law enforcement, working with CrowdStrike and the Shadowserver Foundation, disrupted Sality, a peer-to-peer botnet that has operated since 2003 and infected more than 15,000 machines worldwide. On Monday, CrowdStrike's Counter Adversary Operations team executed a sinkhole operation that isolated infected machines from the botnet's network, cutting off the operator's ability to communicate with them. Once isolated, the bots can no longer receive payload download instructions or direct payload transfers, which the operation's organizers say effectively breaks the botnet.

Sality has distributed a range of malicious code over its lifetime, including credential theft, spam distribution, proxy services, network exploitation and distributed denial-of-service attacks. For the past eight years, its primary payload has been EggJagger, a tool that monitors an infected machine's clipboard for cryptocurrency wallet addresses and silently swaps them for attacker-controlled ones. When a victim then pastes what they think is their own bitcoin or ethereum address to make a payment, the funds go to the criminals instead. CrowdStrike estimates the operator stole at least $150,000 in cryptocurrency through EggJagger alone.

The sinkhole operation worked by attacking the data structure every Sality bot relies on to find other bots: its peer list. Each infected machine keeps a list of super peers, publicly reachable infected machines that form the backbone of the network, and checks every 40 minutes whether those peers are still online, purging any that fail to respond. CrowdStrike's team removed legitimate super peers from bots' peer lists and inserted purpose-built sinkhole entries in their place, progressively isolating more infected machines and giving police and cyber operatives visibility into the operation's progress, which helped them notify victims. "In practice, the operation targeted the data structure at the heart of every bot's network awareness: its peer list," CrowdStrike's Counter Adversary Operations team said in a technical writeup.

Alongside the sinkhole operation, the US Justice Department, the FBI and the Department of Defense Office of Inspector General's Defense Criminal Investigative Service seized Sality-linked domains in the US, while law enforcement in Bulgaria, Hungary and Romania took action against further Sality-linked domains hosted in Europe. The Shadowserver Foundation is now working with internet service providers and Computer Security Incident Response Teams to identify remaining infections and help notify and remediate victims.

Key facts

  • Sality is a peer-to-peer botnet that has run since 2003 and infected more than 15,000 machines worldwide.
  • CrowdStrike, international police and the Shadowserver Foundation disrupted it on Monday with a sinkhole operation that poisoned bots' peer lists.
  • The primary payload for the past eight years has been EggJagger, clipboard-hijacking malware that swaps copied crypto wallet addresses for the attacker's own.
  • CrowdStrike estimates the Sality operator stole at least $150,000 in cryptocurrency through EggJagger alone.
  • US authorities seized Sality-linked domains domestically, and police in Bulgaria, Hungary and Romania seized further domains in Europe.

Why it matters

Sality is one of the longest-running botnets on record, active since 2003, and the takedown shows how a peer-to-peer network can be broken without controlling a central server: by poisoning the peer lists individual bots use to find each other rather than seizing a command point. That technique is reusable against other P2P botnets that rely on the same super-peer discovery mechanism.

Who it affects

More than 15,000 infected machines worldwide, plus anyone whose device was one of them and who copied a cryptocurrency wallet address to make a payment while infected, since EggJagger silently redirected such payments to the attacker. It is also relevant to internet service providers and CSIRTs now coordinating with the Shadowserver Foundation to notify affected users.

How to use it

The Shadowserver Foundation is working with ISPs and CSIRTs to identify infected machines and help notify and remediate victims, so an affected user is more likely to hear about it through their ISP or CSIRT than to find out on their own. Anyone who suspects a machine may have been infected should have it scanned and should double check the destination address on any recent cryptocurrency payment made from it, since EggJagger's clipboard hijacking would not have been visible at the time.

How solid is it

The account comes from CrowdStrike's own technical writeup about an operation it carried out with law enforcement and the Shadowserver Foundation, as reported by The Register; the key figures, the 23-year run, the 15,000-plus infected machines and the $150,000 stolen through EggJagger, are CrowdStrike's own estimates and have not been independently verified in the source. The report does not name Sality's operator or state whether anyone has been arrested.

Risks and caveats

The source describes infected machines as isolated from the botnet's network, not as cleaned of the Sality infection itself, so the underlying malware could persist on those machines even though the operator can no longer reach them. The $150,000 figure is explicitly a minimum estimate covering EggJagger alone, so total losses across Sality's full 23-year history and its other payloads, including credential theft and DDoS activity, are unknown.

“In practice, the operation targeted the data structure at the heart of every bot's network awareness: its peer list.”

— CrowdStrike Counter Adversary Operations team