Overview
- CrowdStrike and U.S. law enforcement led a coordinated takedown that seized Sality-linked domains and sinkholed the botnet so infected machines now report to defender-run nodes.
- CrowdStrike began the technical sinkhole operation on Monday, August 31, using protocol-level peer-list manipulation to replace super peers with sinkholes and isolate bots.
- Sality is a 23-year-old peer-to-peer file-infector that infected more than 15,000 machines and for about eight years mainly delivered the EggJagger clipboard hijacker that CrowdStrike estimates stole at least 12.1 million rubles (roughly $150,000).
- U.S. authorities (DOJ, FBI, DCIS) worked with partners in Bulgaria, Hungary and Romania plus the Shadowserver Foundation to seize payload hosting URLs and coordinate victim notification and cleanup efforts.
- The operator cluster tracked as SALTY SPIDER is assessed to operate from Russia’s Bashkortostan region and has not been publicly identified for prosecution; defenders warn that existing malware remains active and requires manual removal by owners or IT teams.