Sality Botnet Disrupted in International Cyber Operation
Article Content
On August 31, 2026, CrowdStrike, in collaboration with international law enforcement, executed a coordinated disruption of the Sality peer-to-peer botnet, which had been active since 2003 and infected over 15,000 machines globally. The operation involved a peer-to-peer sinkholing strategy that isolated infected devices, effectively severing the botnet's command and control capabilities. Sality was known for distributing various types of malware, including the EggJagger tool, which stole cryptocurrency by altering clipboard contents. The operation was supported by the U.S. Department of Justice, FBI, and law enforcement agencies from Bulgaria, Hungary, and Romania. This disruption marks a significant step in combating long-standing cyber threats and demonstrates the effectiveness of public-private partnerships in cybersecurity.
Key Points: • Sality botnet disrupted after 23 years of operation. • Over 15,000 machines were infected worldwide. • The operation utilized a peer-to-peer sinkholing technique.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.