logo

Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes

ID: 16040ec9-1496-5e62-b250-d673c3154e97

STIX ID: report--16040ec9-1496-5e62-b250-d673c3154e97

Feed Name: The Register (Security)

Threat Score
72/100

Date Published: 2026-09-01

Date Updated: 2026-09-05

...
...

International law enforcement, working with CrowdStrike and Shadowserver Foundation, disrupted the 23-year-old Sality P2P botnet that infected over 15,000 machines and delivered a range of malicious payloads; its primary recent payload, EggJagger, monitored and replaced cryptocurrency wallet addresses to steal funds (estimated at least $150,000). The takedown used a peer-list sinkhole technique to isolate bots, coupled with domain seizures and coordinated victim identification and notification by ISPs and CSIRTs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.