Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes
- ID
- 20581
- Status
- summarized
- Published
- 02 Sep 2026, 7:54 AM
- Fetched
- 02 Sep 2026, 12:40 PM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/cyber-crime/2026/09/02/cops-crowdstrike-disrupt-sality-botnet-by-poisoning-the-network-and-diverting-into-sinkholes/5293795
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 3.5
- Created
- 02 Sep 2026, 12:41 PM
- Tags
- Audience
- developerssaas_founders
What happened
International law enforcement, CrowdStrike, and Shadowserver disrupted Sality, a 23-year-old peer-to-peer botnet infecting 15,000+ machines, by poisoning each bot's peer list and inserting sinkhole entries. Sality's primary payload for the past eight years was EggJagger, a clipboard-monitoring tool that silently replaced copied cryptocurrency wallet addresses with attacker-controlled ones, stealing an estimated $150,000+.
Why it matters
The takedown technique is a notable case study in P2P botnet disruption via peer-list manipulation, but there is no direct action required for this audience. The EggJagger clipboard-replacement attack is a reminder that crypto payment users should verify pasted wallet addresses character-by-character, but this is routine hygiene, not a new threat.
Discussion angle
The peer-list poisoning method is a clever infrastructure-level takedown worth a brief mention, but the practical takeaway for builders is thin — use it as a quick 'how P2P botnets die' segment rather than a deep dive.