Sality Botnet Disrupted in International Cyber Operation

Sality Botnet Disrupted in International Cyber Operation

First seen 2 Sep 2026, 00:28 UTC JusticeTheregisterwww.crowdstrike.com 31.9

Article Content

Browse articles
ThreatCluster

On August 31, 2026, CrowdStrike, in collaboration with international law enforcement, executed a coordinated disruption of the Sality peer-to-peer botnet, which had been active since 2003 and infected over 15,000 machines globally. The operation involved a peer-to-peer sinkholing strategy that isolated infected devices, effectively severing the botnet's command and control capabilities. Sality was known for distributing various types of malware, including the EggJagger tool, which stole cryptocurrency by altering clipboard contents. The operation was supported by the U.S. Department of Justice, FBI, and law enforcement agencies from Bulgaria, Hungary, and Romania. This disruption marks a significant step in combating long-standing cyber threats and demonstrates the effectiveness of public-private partnerships in cybersecurity.

Key Points: • Sality botnet disrupted after 23 years of operation. • Over 15,000 machines were infected worldwide. • The operation utilized a peer-to-peer sinkholing technique.

Timeline

2003-01-01
Sality botnet first observed
Sality malware was identified as a persistent threat on the internet, evolving into a P2P botnet.
CrowdStrike
2026-08-31
Sality botnet disruption operation executed
CrowdStrike and international law enforcement executed a sinkholing operation, isolating infected machines.
CrowdStrike
2026-09-01
Sality disruption announced
The Department of Justice confirmed the multinational operation to disrupt Sality's infrastructure.
Justice
2026-09-01
Sality disruption reported by media
The Register reported details of the disruption operation and its impact on the botnet's network.
Theregister