Sality Botnet Disrupted After 23 Years of Operation

Sality Botnet Disrupted After 23 Years of Operation

First seen 2 Sep 2026, 00:28 UTC GlobalbankingandfinanceUsnewsJusticeTheregisterFirstpost+29 33.8

Article Content

Browse articles
ThreatCluster

On August 31, 2026, CrowdStrike, in collaboration with international law enforcement, executed a coordinated disruption of the Sality peer-to-peer (P2P) botnet, which had been active since 2003. The operation involved a peer-to-peer sinkhole strategy that isolated over 15,000 infected machines worldwide, effectively severing the botnet's communication with its operator. Sality primarily delivered the EggJagger malware, which hijacked clipboard data to redirect cryptocurrency transactions, resulting in an estimated theft of at least $150,000. The operation was supported by the U.S. Department of Justice, FBI, and law enforcement from Bulgaria, Hungary, and Romania, along with the Shadowserver Foundation. Authorities also seized Sality-linked domains to prevent further payload distribution. This disruption marks a significant victory against a long-standing cyber threat.

Key Points: • Sality botnet disrupted after 23 years, affecting over 15,000 machines globally. • The primary payload, EggJagger, redirected cryptocurrency transactions, stealing at least $150,000. • The operation involved multiple international law enforcement agencies and private sector partners.

Ask AI about this cluster

Timeline

2003-01-01
Sality first observed
Sality malware was first identified as a file-infecting virus.
CrowdStrike
2026-08-31
Sality botnet disruption operation
CrowdStrike and law enforcement executed a sinkhole operation, isolating infected machines.
CrowdStrike
2026-09-01
Announcement of disruption
U.S. Department of Justice announced the successful disruption of the Sality botnet.
Justice
2026-09-02
Details of the operation released
Further details about the sinkhole operation and its impact were published by various outlets.
The Register