Global Law Enforcement and CrowdStrike Dismantle 23-Year-Old Sality Botnet
An international law enforcement operation, in collaboration with CrowdStrike, has successfully disrupted the Sality botnet, a persistent threat active since 2003.

International law enforcement agencies, working in concert with cybersecurity firm CrowdStrike and the Shadowserver Foundation, have announced the takedown of the Sality botnet, a notorious peer-to-peer network that has been active for over two decades. This operation marks a significant blow against a long-standing cybercrime infrastructure that has been used to distribute a wide array of malware to more than 15,000 infected machines globally since its inception in 2003.
The Sality botnet's versatility allowed its operators to deploy various malicious payloads, including tools for credential theft, spam distribution, proxy services, network exploitation, and distributed denial-of-service (DDoS) attacks. For the past eight years, a primary function of the botnet has been the distribution of the EggJagger malware. This sophisticated tool operates by monitoring a victim's clipboard for cryptocurrency wallet addresses and silently replacing them with addresses controlled by the attackers. This insidious mechanism allowed Sality operators to intercept and divert cryptocurrency transactions, with CrowdStrike estimating that at least $150,000 was stolen through EggJagger alone.
The disruption strategy, executed by CrowdStrike's Counter Adversary Operations team, involved a complex peer-to-peer sinkhole operation. This technical maneuver effectively isolated infected machines from the botnet's command-and-control infrastructure, severing the attackers' ability to communicate with and control the compromised devices. By isolating the bots, they could no longer receive instructions for payload downloads or direct payload transfers, thereby rendering the botnet inoperable.
CrowdStrike detailed the technical approach, explaining that the operation targeted the core data structure of each bot's network awareness: its peer list. Sality bots maintain a list of 'super peers'—publicly accessible infected machines that form the backbone of the P2P network. Bots regularly check the availability of these peers, purging those that fail to respond. The counterattack exploited this by systematically removing legitimate super peers from the bots' lists and inserting purpose-built sinkhole entries. This strategy progressively isolated more infected machines and provided law enforcement with visibility into the operation's progress, aiding in victim notification.
In parallel with the technical takedown, law enforcement agencies worldwide took coordinated action against Sality's infrastructure. The U.S. Justice Department, FBI, and the Department of Defense Office of Inspector General’s Defense Criminal Investigative Service seized Sality-linked domains within the United States. Simultaneously, international law enforcement in Bulgaria, Hungary, and Romania took action against additional Sality-associated domains hosted in Europe, further dismantling the botnet's operational capabilities.
The Shadowserver Foundation is now actively collaborating with internet service providers (ISPs) and Computer Security Incident Response Teams (CSIRTs) globally. Their efforts are focused on identifying remaining infections, notifying affected users, and facilitating remediation processes to help victims clean their systems and prevent reinfection.
The successful disruption of the Sality botnet highlights the effectiveness of international cooperation between law enforcement, cybersecurity firms, and non-profit organizations in combating persistent cyber threats. The longevity of Sality underscores the challenges in eradicating deeply entrenched botnets, while its takedown demonstrates a sophisticated approach to network disruption and infrastructure seizure.