Back Cyberinsider US and European authorities disrupt Sality botnet after 23 years
US and European law enforcement agencies have disrupted the long-running Sality malware operation, cutting its operators off from more than 15,000 infected computers worldwide.
The coordinated action, carried out on August 31, involved the US Department of Justice, FBI, Defense Criminal Investigative Service (DCIS), CrowdStrike, the Shadowserver Foundation, and Europol.
CrowdStrike’s Counter Adversary Operations team said investigators neutralized Sality through a peer-to-peer sinkholing operation that manipulated the botnet’s own networking mechanism, isolating infected systems from infrastructure controlled by the malware operator.
First observed in 2003, Sality is a polymorphic file-infecting malware family that spreads by attaching itself to executable files and propagating through network shares, removable drives, and file-sharing activity. Unlike conventional botnets that rely on centralized command-and-control servers, Sality evolved into a decentralized peer-to-peer network in which infected computers communicated directly with one another.
That architecture helped Sality survive takedown attempts for more than two decades. Two separate networks, known as versions 3 and 4, remained active until this week's operation.
Sality itself primarily acted as a malware delivery platform. Over the years, operators used it to install credential stealers, spam tools, proxies, network exploitation malware, and distributed denial-of-service tools.
For roughly the past eight years, its main payload was EggJagger, a clipboard-hijacking malware that detects copied Bitcoin and Ethereum wallet addresses and replaces them with addresses controlled by the attacker.
CrowdStrike estimates EggJagger stole at least 12.1 million rubles, approximately $150,000, in cryptocurrency. The value of cryptocurrency held in associated wallets reportedly peaked at roughly 147 million rubles in January 2025.
Researchers also linked Sality to several DDoS incidents, including attacks against an Arabic-language financial forum in 2016, a Ukrainian web forum discussing Russia's invasion of Ukraine in February 2022, and Russian cryptocurrency exchange AvanChange in 2023.
Turning Sality's P2P network against it
The disruption exploited a weakness in Sality's peer-management protocol.
Each infected computer maintains a finite list of publicly reachable “super peers” and periodically checks whether those systems remain online. CrowdStrike and its partners manipulated those lists to remove legitimate Sality peers and replace them with controlled sinkhole servers.
Because Sality performs no authentication of peers joining the network, the sinkholes could appear as legitimate participants. Infected systems gradually became isolated from the operator and could no longer receive new payload download instructions or malware files.
Authorities also seized Sality-related domains in the United States, while investigators in Bulgaria, Hungary, and Romania acted against additional infrastructure hosted in Europe.
Shadowserver is now working with internet providers and incident response teams to identify affected systems and notify victims.
CrowdStrike warned that disruption of the command channel does not remove malware already installed on compromised machines.
Network defenders can check for UDP connections to the sinkhole address 188.166.101[.]148, which confirms a Sality infection. Organizations should also scan systems using the published Sality v3 and v4 YARA rules and review connections to the disclosed payload URLs.
FBI Disrupts Massive Botnet with Over 260,000 Compromised Devices
International Law Enforcement Operation Dismantles QBot Botnet
US Disrupts Chinese Botnet Supporting Attacks on Critical Systems
Botnet Operator Charged with Major Cyber Crimes in the U.S.
French Authorities Dismantle PlugX Botnet Ahead of Paris 2024 Olympics
US Authorities Shut Down Rapper Bot Malware and Charged Admin
Amar Ćemanović is an experienced editor and trained engineer with a keen eye for detail and a passion for technology. Based in Bosnia, Amar specializes in producing high-quality, engaging content. He holds a Master’s degree in engineering, which helps him maintain a meticulous approach to all editorial work. Amar brings a well-rounded knowledge base, covering everything from tech solutions to privacy tools.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
