Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes
ID: 16040ec9-1496-5e62-b250-d673c3154e97
STIX ID: report--16040ec9-1496-5e62-b250-d673c3154e97
Feed Name: The Register (Security)
International law enforcement, working with CrowdStrike and Shadowserver Foundation, disrupted the 23-year-old Sality P2P botnet that infected over 15,000 machines and delivered a range of malicious payloads; its primary recent payload, EggJagger, monitored and replaced cryptocurrency wallet addresses to steal funds (estimated at least $150,000). The takedown used a peer-list sinkhole technique to isolate bots, coupled with domain seizures and coordinated victim identification and notification by ISPs and CSIRTs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
