International Takedown Disrupts Sality Botnet After More Than 20 Years
International law enforcement agencies and cybersecurity companies have disrupted the Sality botnet, a peer-to-peer (P2P) malware network that operated for more than two decades.
As part of the coordinated operation, Europol, Eurojust, the U.S. Department of Justice (DOJ), the FBI, and the Defense Criminal Investigative Service (DCIS) seized Sality-related domains in the United States. Authorities in Bulgaria, Hungary, and Romania also seized additional domains hosted in Europe.
CrowdStrike’s Counter Adversary Operations team worked with international law enforcement agencies and private-sector partners to dismantle the botnet’s control infrastructure. Investigators used peer-to-peer sinkholing operations to isolate infected computers and disrupt communications between Sality-infected devices.
The Sality malware botnet has been active since at least 2003 and has infected more than 15,000 devices over the course of its operation. CrowdStrike says Sality was operated by criminal groups tracked as Salty Spider, which may be based in Russia’s Bashkortostan region.
“The Sality-infected victim’s computer was part of a peer-to-peer (P2P) botnet, a network of computers (each a ‘bot’) infected with Sality malware and controlled by a Sality operator,” the U.S. Department of Justice said.
According to CrowdStrike, two separate Sality botnet networks remained active before the takedown. The networks were primarily used to distribute EggJagger malware in cryptocurrency clipjacking attacks.
“Throughout its history, Sality has distributed a wide variety of different malware families ranging from credential theft, spam distribution, proxy services, network abuse, and distributed denial-of-service (DDoS) attacks,” CrowdStrike said. “For the past eight years, the primary payload has been EggJagger, a clipjacking tool that monitors crypto wallet addresses in the clipboard and silently replaces them with operator-controlled addresses.”

How the Sality botnet takedown worked
The P2P botnet was disrupted by sinkholing Sality’s known list of superpeers, which formed the network’s communication backbone. The operation blocked the distribution of file packs, which contained malware payloads, and URL packs, which contained instructions for downloading additional payloads.
The sinkhole operation also prevented malicious data from being propagated to infected machines and removed Sality-related entries from the peer lists used by compromised devices.
“After more than 20 years of continuous operations, CrowdStrike, in collaboration with international law enforcement and industry partners, conducted successful disruption operations against the Sality botnet, which is now no longer under the operator’s control,” the cybersecurity company said.
More international botnet takedowns
The Sality disruption is the latest in a series of international operations targeting cybercrime infrastructure.
In March, U.S. and European authorities, together with private-sector partners, disrupted the SocksEscort cybercrime proxy network. The operation also targeted command-and-control (C2) infrastructure associated with the Aisuru, KimWolf, JackSkid, and Mossad botnets.
More recently, in May, Dutch authorities took a massive botnet made up of 17 million devices offline. In a separate FBI-led operation, authorities disrupted the QScan and QTRouter hacking platforms reportedly used by Chinese cyberespionage groups.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop dramatically.
The Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com



