Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2636+ Articles
163+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Sality Botnet Infrastructure Dismantled in Joint Global Takedown
Sality Botnet Infrastructure Dismantled in Joint Global Takedown
NEWS

Sality Botnet Infrastructure Dismantled in Joint Global Takedown

Law enforcement and CrowdStrike sinkholed the 20+ year-old Sality P2P botnet, cutting off operator SALTY SPIDER's control channels.

Dylan H.

News Desk

September 2, 2026
2 min read

Two Decades of Operation Come to an End

International law enforcement and private industry partners have seized infrastructure belonging to Sality, a peer-to-peer botnet that has been operating continuously since 2003 — making it one of the longest-running pieces of active malware infrastructure ever dismantled. The joint action targeted domains and command channels tied to the botnet in both the United States and Europe.


Who Was Involved

  • U.S. Department of Justice and the FBI
  • Europol and Eurojust
  • National authorities from Bulgaria, Hungary, and Romania
  • CrowdStrike's Counter Adversary Operations team, which ran the technical sinkholing effort
  • Additional private-industry partners

Sality is attributed to a criminal group tracked as SALTY SPIDER, believed to be based in Russia's Republic of Bashkortostan.


How the Takedown Worked

CrowdStrike executed what it describes as a peer-to-peer sinkhole operation, targeting the "super peers" that act as the communication backbone for Sality's decentralized architecture. Because Sality doesn't rely on centralized command-and-control servers the way many botnets do, disrupting it required isolating and sinkholing these super peers directly rather than simply seizing a handful of C2 domains — a technically harder takedown than a conventional botnet disruption.

At the time of takedown, Sality's two active networks were primarily distributing EggJagger, a clipboard-hijacking ("clipjacking") tool that monitors for cryptocurrency wallet addresses and silently swaps them for attacker-controlled addresses. Over its lifetime, the botnet has been used to push a much broader range of payloads: credential stealers, spam infrastructure, proxy services, network exploitation tools, and DDoS capability, infecting more than 15,000 devices across its history.


Why It Matters

Sality's longevity is the story here. Most botnets get dismantled within a few years of gaining law enforcement attention; Sality survived more than two decades by leaning on a resilient, decentralized peer-to-peer architecture that doesn't depend on any single point of failure. Its final act — a clipjacker quietly swapping crypto addresses in the clipboard — is a reminder that legacy infrastructure doesn't have to be sophisticated to keep generating profit for its operators; it just has to keep running. This takedown closes out one of the internet's oldest continuously operating criminal networks.

Related Reading

  • FBI ATM Jackpotting Surge Nets $20 Million
  • DOJ Disrupts 3 Million-Device IoT Botnets Behind Record 314 Tbps Global DDoS Attack
#Sality#Botnet#Takedown#Law Enforcement#CrowdStrike#P2P Malware

Related Articles

CrowdStrike Dismantles Glassworm Botnet Targeting Open-Source Supply Chain

CrowdStrike, Google, and Shadowserver dismantled the Glassworm botnet, stripping operators of infrastructure used to inject malware into OSS packages.

4 min read

GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure

CrowdStrike, Google, and Shadowserver simultaneously disrupted GlassWorm C2 channels, ending a supply-chain campaign targeting developers via packages.

4 min read

ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache

This week's ThreatsDay Bulletin from The Hacker News covers 20 active threats including a hybrid P2P DDoS botnet, a 13-year-old Apache ActiveMQ RCE flaw...

4 min read
Back to all News