Sality Takedown Isolates 15,000 Machines Used in Crypto Theft

CrowdStrike and the U.S. Department of Justice disrupted the Sality botnet, isolating more than 15,000 infected machines that had been used to distribute malicious payloads. Active since 2003, Sality spent the past eight years primarily delivering EggJagger, a tool that monitored copied cryptocurrency wallet addresses and replaced them with addresses controlled by its operator.
The operation targeted a damaging weakness in cryptocurrency payment workflows. When malware changes an address before a payment is completed, funds can be redirected to a different recipient. CrowdStrike estimates that EggJagger alone was responsible for at least 12.1 million rubles, or roughly $150,000, in stolen cryptocurrency.
Today the @FBI, @TheJusticeDept, and the Defense Criminal Investigative Service (DCIS) announced a multinational operation with actions in the United States and Europe to disrupt the botnet known as Sality.
Since 2003, the Sality botnet has installed malware on compromised… pic.twitter.com/HNIY3oCGYr
… Continue reading the full article at the original source below.

