• A botnet running for 23 years with over 15,000 endpoints has fina

    From TechnologyDaily@1337:1/100 to All on Wednesday, September 02, 2026 15:30:23
    A botnet running for 23 years with over 15,000 endpoints has finally been
    shut down by law enforcement and Crowdstrike

    Date:
    Wed, 02 Sep 2026 14:25:00 +0000

    Description:
    Crowdstrike and friends sinkholed thousands of Sality's endpoints rendering the botnet useless.

    FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Crowdstrike and law enforcement disrupted Sality , a peertopeer botnet active since 2003 Botnet spread
    malware and clipboard hijacker EggJagger , stealing $150K in cryptocurrency Operation sinkholed endpoints and removed payload URLs, coordinated with DOJ, FBI, Europol, and others Security experts Crowdstrike, together with a
    handful of national and international law enforcement agencies, finally managed to disrupt Sality, a peer-to-peer botnet that operated unabated for more than two decades.

    Sality first emerged in 2003. Unlike classic botnets which receive instructions and report back to a single, central entity, this botnets endpoints (some 15,000 of them) communicated among themselves, which made it more difficult to track and destroy. Throughout its long history, Salitys key feature was to deploy additional payloads to infected machines. The endpoints were being poisoned with a wide variety of different malware that facilitated credential theft, spam, proxy services, and distributed denial of service (DDoS) attacks. However, between 2018 and today, Sality was primarily used to deploy EggJagger, a clipboard hijacking tool seen in cryptocurrency theft. Latest Videos From TechRadar Watch full video here: Sinkholing the botnet Cryptocurrency wallet addresses are a long string of random characters, which are almost impossible, and definitely impractical, to remember by heart. Instead, when users want to send their money, they simply copy and paste the recipients wallet address into their own. EggJagger monitors this behavior, and when it spots something resembling a wallet address being copied, it replaces the string in the clipboard. Thus, when the victim hits paste, they end up adding the attackers wallet address instead.

    According to Crowdstrike, from this malware alone, Salitys operators raked in more than $150,000. You may like '27 million stolen login credentials have been recovered': Global coordinated takedown hits SocGholish, Amadey, and StealC malware networks where it hurt Thousands of D-Link and QNAP NAS
    routers compromised by fast-moving AryStinger malware that turns unsecured devices into a malicious proxy botnet Even dead websites aren't safe experts warn hackers are spending millions on expired domains to enable malware scams

    The researchers disrupted the botnet by sinkholing the endpoints. They first added a few of their own devices into the botnet and whenever others tried to communicate with them, the researchers would purge their peers list, essentially blinding them.

    Crowdstrike also coordinated with international law enforcement to take down the URLs that were hosting the botnets payloads. Disrupting Salitys ability
    to download these files ensures that bots still carrying active URL packs cannot retrieve new payloads during the transition period, they explained.
    Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

    The operation was carried out in partnership with the US Department of
    Justice (DOJ), the Federal Bureau of Investigation (FBI), the Department of Defense Office of Inspector Generals Defense Criminal Investigative Service (DCIS), and the Shadowserver Foundation, with support from Europol, Eurojust, and law enforcement agencies in Bulgaria, Hungary, and Romania.

    We also acknowledge additional unnamed partners whose contributions were essential to the success of this operation, Crowdstrike concluded.

    Via The Register The best antivirus for all budgets Our top picks, based on real-world testing and comparisons

    Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/a-botnet-running-for-23-years-with-over -15-000-endpoints-has-finally-been-shut-down-by-law-enforcement-and-crowdstrik e


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)