September 02, 11:30

CrowdStrike and Justice Department dismantle Sality after eight years of crypto theft

Sality Botnet Dismantled After Eight Years of Stealing Bitcoin and Ethereum

Decrypt

CrowdStrike and the Justice Department dismantled the Sality botnet. Sality had circulated since 2003. Its EggJagger payload stole at least 12.1 million rubles, or roughly $150,000. EggJagger monitored cryptocurrency wallet addresses copied to infected computers. The malware replaced those addresses with the operator's addresses. Victims then sent Bitcoin or Ethereum payments to the operator. CrowdStrike valued the largely untouched stolen portfolio at about 147 million rubles at its peak in January 2025. The portfolio had a nominal value of $1.35 million. CrowdStrike compared that value with roughly $4 million in purchasing power in a Western capital. Before EggJagger, Sality delivered credential theft payloads. It also delivered spam payloads. It delivered proxy service payloads. It delivered denial-of-service payloads. Sality had no central server that authorities could seize. Infected machines communicated directly with one another. The malware spread through executable files transferred over network shares and removable drives. Bots accepted reachable machines that answered the handshake correctly. The bots did not check who was joining. CrowdStrike's Counter Adversary Operations team used that access to remove legitimate peers from each bot's address list. The team inserted its own sinkholes. The operation isolated more than 15,000 machines worldwide. The Justice Department, FBI and Defense Criminal Investigative Service seized Sality-linked domains in the United States. Police in Bulgaria, Hungary and Romania took down other domains in Europe. The Shadowserver Foundation is working with internet providers to notify victims. CrowdStrike tracks the operator as SALTY SPIDER. The operator occasionally used the botnet against targets. A denial-of-service payload hit the Russian cryptocurrency exchange AvanChange in September 2023. The payload was compiled seconds before it was uploaded. CrowdStrike interpreted the timing as an impulsive response to a personal grievance. CrowdStrike believes the operator used cryptocurrency exchanges such as AvanChange to convert stolen coins into cash. Infected machines now report to CrowdStrike-controlled sinkholes instead of the operator. CrowdStrike published detection rules and network indicators. Malware already on those machines remains active until someone removes it.

This content is an AI-generated summary/analysis for informational purposes only and does not constitute investment advice.