bleeping-computer · Crawled Sep 2, 2026

Sality botnet infrastructure dismantled in joint global takedown

1 Actors 1 Malware
Read original article ↗

AI Summary

The Sality botnet, active for over two decades and responsible for infecting more than 15,000 devices, has been disrupted in a joint global takedown operation led by international law enforcement and private sector partners including Europol, FBI, and CrowdStrike. The botnet, attributed to the threat actor group SALTY SPIDER believed to be operating from Russia's Republic of Bashkortostan, used a peer-to-peer (P2P) architecture to distribute malware payloads, primarily EggJagger in recent years. EggJagger is a clipjacking tool that monitors and replaces cryptocurrency wallet addresses in the clipboard with attacker-controlled ones. The disruption was achieved by sinkholing the botnet’s super peer infrastructure, effectively severing communication between infected machines and preventing further propagation of malicious payloads.

AI-extracted · verify before operational use

Extracted Entities 2 found

MITRE ATT&CK TTPs 5 techniques