Sality botnet infrastructure dismantled in joint global takedown

Sality

International law enforcement agencies and private partners have seized Sality malware infrastructure in a joint action aiming to disrupt and take down the peer-to-peer (P2P) botnet.

As part of this operation, supported by Europol and Eurojust, the U.S. Department of Justice (DOJ), FBI, and DCIS seized Sality-linked domains in the United States, while authorities in Bulgaria, Hungary, and Romania seized additional Sality-linked domains hosted in Europe.

CrowdStrike's Counter Adversary Operations team, in collaboration with international law enforcement and private industry partners, also dismantled the botnet's control channels in a peer-to-peer sinkhole operation that isolated infected machines.

The Sality botnet has been active for more than two decades and has infected over 15,000 devices with malware since at least 2003, when it first surfaced. CrowdStrike says Sality is controlled by a criminal group it tracks as SALTY SPIDER, which is likely operating out of the Republic of Bashkortostan in Russia.

"The victim computers infected with Sality were part of a peer-to-peer (P2P) botnet, which is a network of computers (each a 'bot) infected with the Sality malware and controlled by the Sality operator," the DOJ said.

According to CrowdStrike, the two separate Sality botnet networks that were still active when the takedown took place this week were mainly used to push EggJagger malware payloads in clipjacking attacks.

"Throughout its history, Sality distributed a wide variety of distinct malware families spanning credential theft, spam distribution, proxy services, network exploitation, and distributed denial-of-service (DDoS) attacks," CrowdStrike said. "For the past eight years, the primary payload has been EggJagger, a clipjacking tool that monitors the clipboard for cryptocurrency wallet addresses and silently replaces them with addresses controlled by the operator."

Sality infected devices
Sality infected devices (CrowdStrike)

​The P2P botnet was disrupted by sinkholing Sality's list of known super peers, which form its communication backbone, to block file packs (direct payload transfers) and URL packs (payload download instructions) from propagating and purging infected machines' peer lists.

"After more than two decades of continuous operation, CrowdStrike, together with international law enforcement and industry partners, conducted a successful disruption operation against the Sality botnet, which is now no longer under the operator's control," the cybersecurity company added.

Law enforcement agencies worldwide have dismantled multiple other cybercrime operations since the start of the year as part of international joint actions.

In March, American and European authorities, along with private partners, disrupted the SocksEscort cybercrime proxy network and took down Command and Control (C2) infrastructure used by the Aisuru, KimWolf, JackSkid, and Mossad botnets.

More recently, Dutch authorities took a massive botnet of 17 million devices offline in May, and an FBI-led operation disrupted the QScan and QTRouter hacking platforms used by Chinese cyber-espionage groups.

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report
source: BleepingComputer