VYPR
breachPublished Sep 1, 2026· Updated Sep 3, 2026· 9 sources

Global Law Enforcement and CrowdStrike Dismantle 23-Year-Old Sality Botnet

An international law enforcement operation, in collaboration with CrowdStrike, has successfully disrupted the Sality botnet, a persistent threat active since 2003.

International law enforcement agencies, working in concert with cybersecurity firm CrowdStrike and the Shadowserver Foundation, have announced the takedown of the Sality botnet, a notorious peer-to-peer network that has been active for over two decades. This operation marks a significant blow against a long-standing cybercrime infrastructure that has been used to distribute a wide array of malware to more than 15,000 infected machines globally since its inception in 2003.

The Sality botnet's versatility allowed its operators to deploy various malicious payloads, including tools for credential theft, spam distribution, proxy services, network exploitation, and distributed denial-of-service (DDoS) attacks. For the past eight years, a primary function of the botnet has been the distribution of the EggJagger malware. This sophisticated tool operates by monitoring a victim's clipboard for cryptocurrency wallet addresses and silently replacing them with addresses controlled by the attackers. This insidious mechanism allowed Sality operators to intercept and divert cryptocurrency transactions, with CrowdStrike estimating that at least $150,000 was stolen through EggJagger alone.

The disruption strategy, executed by CrowdStrike's Counter Adversary Operations team, involved a complex peer-to-peer sinkhole operation. This technical maneuver effectively isolated infected machines from the botnet's command-and-control infrastructure, severing the attackers' ability to communicate with and control the compromised devices. By isolating the bots, they could no longer receive instructions for payload downloads or direct payload transfers, thereby rendering the botnet inoperable.

CrowdStrike detailed the technical approach, explaining that the operation targeted the core data structure of each bot's network awareness: its peer list. Sality bots maintain a list of 'super peers'—publicly accessible infected machines that form the backbone of the P2P network. Bots regularly check the availability of these peers, purging those that fail to respond. The counterattack exploited this by systematically removing legitimate super peers from the bots' lists and inserting purpose-built sinkhole entries. This strategy progressively isolated more infected machines and provided law enforcement with visibility into the operation's progress, aiding in victim notification.

In parallel with the technical takedown, law enforcement agencies worldwide took coordinated action against Sality's infrastructure. The U.S. Justice Department, FBI, and the Department of Defense Office of Inspector General’s Defense Criminal Investigative Service seized Sality-linked domains within the United States. Simultaneously, international law enforcement in Bulgaria, Hungary, and Romania took action against additional Sality-associated domains hosted in Europe, further dismantling the botnet's operational capabilities.

The Shadowserver Foundation is now actively collaborating with internet service providers (ISPs) and Computer Security Incident Response Teams (CSIRTs) globally. Their efforts are focused on identifying remaining infections, notifying affected users, and facilitating remediation processes to help victims clean their systems and prevent reinfection.

The successful disruption of the Sality botnet highlights the effectiveness of international cooperation between law enforcement, cybersecurity firms, and non-profit organizations in combating persistent cyber threats. The longevity of Sality underscores the challenges in eradicating deeply entrenched botnets, while its takedown demonstrates a sophisticated approach to network disruption and infrastructure seizure.

This CrowdStrike report provides a deeper dive into the technical aspects of the Sality botnet disruption, detailing the specific tactics, techniques, and procedures (TTPs) employed by the botnet and how they were countered during the operation. It highlights the collaborative efforts between law enforcement agencies and cybersecurity firms in dismantling the sophisticated, long-standing botnet infrastructure.

The disruption operation involved a multi-pronged approach. CrowdStrike manipulated the botnet's peer lists at the protocol level, progressively isolating infected machines and injecting sinkholes. Concurrently, law enforcement agencies in the US, Bulgaria, Hungary, and Romania targeted and took down the URLs used for Sality payload distribution, preventing infected machines from receiving new malware. The Shadowserver Foundation is now assisting ISPs and CSIRTs in identifying and cleaning up remaining infections.

This operation successfully severed the operator's control over an estimated 15,000 infected machines globally, marking a significant blow to a threat that has persisted since 2003. The Sality botnet was known for its file-infecting capabilities, attaching itself to executable programs and spreading through their use.

This operation, involving U.S. and European authorities alongside cybersecurity firm CrowdStrike and the Shadowserver Foundation, successfully severed connections for over 15,000 infected computers by injecting false information into the botnet's peer-to-peer 'super peer' lists. While no arrests were announced, CrowdStrike assesses the operators are likely based in Russia's Bashkortostan region, and authorities seized Sality-linked domains in the U.S. and Europe.

This latest report details the specific operational aspects of the takedown, including the use of P2P sinkholing by CrowdStrike and domain seizures across the United States, Bulgaria, Hungary, and Romania. It also highlights the involvement of the Department of Defense's Defense Criminal Investigative Service (DCIS) and the Shadowserver Foundation in identifying remaining infections and aiding remediation efforts.

The takedown of the Sality botnet, a Russia-based operation active for 23 years and infecting over 11 million devices, was a significant achievement for international law enforcement and cybersecurity firms. CrowdStrike detailed how they exploited the botnet's decentralized peer-to-peer architecture, which had previously made it resilient, by targeting its peer list. This action effectively severed infected machines from the botnet's control, rendering the malware-spreading operation irrecoverable and marking a major blow against a long-standing cyber threat.

This latest report from GovInfoSecurity details the specific technical mechanism used in the disruption: the exploitation of the Sality botnet's own peer-to-peer protocol to isolate infected machines. It also highlights the involvement of U.S. and European authorities alongside cybersecurity firms like CrowdStrike and Shadowserver in this multi-national effort.

This operation, which took place on August 31, involved a multi-national effort including authorities from Bulgaria, Hungary, Romania, and the US, with crucial support from Europol and private sector partners CrowdStrike and the Shadowserver Foundation. The disruption focused on sinkholing the botnet's peer-to-peer infrastructure, a complex task given its decentralized nature, and involved redirecting communications from infected machines to aid in victim notification and progress tracking.

Synthesized by Vypr AI