Sality Botnet Disrupted After 23 Years of Operation
Article Content
On August 31, 2026, CrowdStrike, in collaboration with international law enforcement, executed a coordinated disruption of the Sality peer-to-peer (P2P) botnet, which had been active since 2003. The operation involved a peer-to-peer sinkhole strategy that isolated over 15,000 infected machines worldwide, effectively severing the botnet's communication with its operator. Sality primarily delivered the EggJagger malware, which hijacked clipboard data to redirect cryptocurrency transactions, resulting in an estimated theft of at least $150,000. The operation was supported by the U.S. Department of Justice, FBI, and law enforcement from Bulgaria, Hungary, and Romania, along with the Shadowserver Foundation. Authorities also seized Sality-linked domains to prevent further payload distribution. This disruption marks a significant victory against a long-standing cyber threat.
Key Points: • Sality botnet disrupted after 23 years, affecting over 15,000 machines globally. • The primary payload, EggJagger, redirected cryptocurrency transactions, stealing at least $150,000. • The operation involved multiple international law enforcement agencies and private sector partners.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.