Two Decades of Operation Come to an End
International law enforcement and private industry partners have seized infrastructure belonging to Sality, a peer-to-peer botnet that has been operating continuously since 2003 — making it one of the longest-running pieces of active malware infrastructure ever dismantled. The joint action targeted domains and command channels tied to the botnet in both the United States and Europe.
Who Was Involved
- U.S. Department of Justice and the FBI
- Europol and Eurojust
- National authorities from Bulgaria, Hungary, and Romania
- CrowdStrike's Counter Adversary Operations team, which ran the technical sinkholing effort
- Additional private-industry partners
Sality is attributed to a criminal group tracked as SALTY SPIDER, believed to be based in Russia's Republic of Bashkortostan.
How the Takedown Worked
CrowdStrike executed what it describes as a peer-to-peer sinkhole operation, targeting the "super peers" that act as the communication backbone for Sality's decentralized architecture. Because Sality doesn't rely on centralized command-and-control servers the way many botnets do, disrupting it required isolating and sinkholing these super peers directly rather than simply seizing a handful of C2 domains — a technically harder takedown than a conventional botnet disruption.
At the time of takedown, Sality's two active networks were primarily distributing EggJagger, a clipboard-hijacking ("clipjacking") tool that monitors for cryptocurrency wallet addresses and silently swaps them for attacker-controlled addresses. Over its lifetime, the botnet has been used to push a much broader range of payloads: credential stealers, spam infrastructure, proxy services, network exploitation tools, and DDoS capability, infecting more than 15,000 devices across its history.
Why It Matters
Sality's longevity is the story here. Most botnets get dismantled within a few years of gaining law enforcement attention; Sality survived more than two decades by leaning on a resilient, decentralized peer-to-peer architecture that doesn't depend on any single point of failure. Its final act — a clipjacker quietly swapping crypto addresses in the clipboard — is a reminder that legacy infrastructure doesn't have to be sophisticated to keep generating profit for its operators; it just has to keep running. This takedown closes out one of the internet's oldest continuously operating criminal networks.