Skip to content
Researchers Take Down 20-Year-Old Russian Botnet

Researchers Take Down 20-Year-Old Russian Botnet

Silicon September 2, 2026

CrowdStrike began a public takedown of the Sality botnet at its Day Zero security conference in Las Vegas on Tuesday, in the latest attempt to neutralise the robust, two-decade-old threat network believed to operate out of Russia.

The company said it worked with the FBI and the Department of Justice, which in turn said they cooperated with European law enforcement and other organisations on the takedown.

The botnet operates out of devices such as routers that have been taken over , with criminals using the network to send spam, carry out denial-of-service attacks, and steal cryptocurrency.

‘Clear and present danger’

“Cybercriminals, botnets, and malware are a clear and present danger to our nation’s security and economy,” said first assistant United States attorney Bill Essayli in a statement.

The Sality botnet was first identified in 2003 as a file-infecting malware that was later upgraded at least three times to use more advanced peer-to-peer networks.

In the summer of 2017, the network grew rapidly when its operators began exploiting the EternalBlue vulnerability that was also used by the destructive NotPetya and WannaCry malware strains.

CrowdStrike said the malware was built to be highly resilient, meaning the takedown involved painstaking reverse-engineering work.

The company said it fed malicious data into the peer-to-peer network, causing devices that had been taken over to cut themselves off from the group controlling it, which it designates Salty Spider.

Salty Spider, which CrowdStrike believes to operate out of the Russian province of Bashkortostan, near the Kazakhstan border, may still attempt to regain control of or reform the botnet, security firm The Shadowserver Foundation told Reuters.

Extracted Entities

Attack Types (2)

Malware (2)

Ransomware Groups (1)

Vulnerabilities (1)