Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
CrowdStrike and US authorities dismantle Russian Sality malware operation after two decades
00

CrowdStrike and US authorities dismantle Russian Sality malware operation after two decades

Sep 3, 2026

U.S. law enforcement and cybersecurity firm CrowdStrike have dismantled Sality, a highly resilient Russian botnet operating since 2003. By exploiting a security flaw in Sality's peer-to-peer architecture, CrowdStrike injected false data to disconnect over 15,000 infected computers from their controller. Sality had spent the last eight years using its 'EggJagger' payload to hijack cryptocurrency clipboards, stealing at least $150,000. The international operation was coordinated with European authorities.

Sality botnet takedown operation

  • ▪CrowdStrike researcher Tillmann Werner stated that reverse-engineering Sality's structure and building the infrastructure to knock it down was the most complex botnet takeover the company has ever executed.
  • ▪CrowdStrike began dismantling the Sality botnet on August 31, 2026, during a live demonstration at the company's Day Zero threat intelligence summit in Las Vegas.
  • ▪United States law enforcement officials and cybersecurity company CrowdStrike announced on September 1, 2026, the dismantling of a two-decade-old Russian hacking operation named Sality.
  • ▪United States authorities seized the web domains used by Sality operators to control infected machines, while CrowdStrike worked to break the remaining connections.

Peer-to-peer architecture resilience

  • ▪Sality survived for over two decades because it spread by infecting executable files and lacked a central machine that authorities could easily take offline.
  • ▪Sality utilized a peer-to-peer architecture without a central command server, allowing infected machines to communicate directly and check peer online status every 40 minutes.
  • ▪CrowdStrike disrupted the Sality botnet by seeding the peer-to-peer network with false information, tricking more than 15,000 infected machines into cutting themselves off from their creator.

Cryptocurrency clipboard hijacking

  • ▪Sality used a clipjacking tool named EggJagger to monitor clipboards on infected devices and silently replace copied Bitcoin or Ethereum wallet addresses with addresses controlled by the operators.
  • ▪The value of the unspent cryptocurrency stolen by Sality operators peaked at approximately $1.35 million to $1.5 million in early 2025 as digital asset prices rose.
  • ▪Sality operators stole at least 12.1 million rubles, or approximately $150,000, in cryptocurrency over an eight-year period using clipboard hijacking techniques.

International law enforcement coordination

  • ▪The United States Justice Department stated that the Sality cybercrime operation was based out of Russia, though further details were not provided.
  • ▪The United States Federal Bureau of Investigation and Department of Justice coordinated the Sality takedown with law enforcement officials from Bulgaria, Hungary, and Romania.
  • ▪The Russian Embassy in Washington did not immediately respond to requests for comment regarding the Sality botnet takedown.

Legacy malware persistence risks

  • ▪Sality was first spotted in 2003, making it one of the internet's longest-running cybercriminal enterprises despite being overshadowed in recent years by ransom-seeking cybercriminals.
  • ▪Legacy Sality infections persist because compromised machines, small business servers, and industrial systems in regions like Europe are rarely patched or monitored by their owners.
  • ▪David Watson of the nonprofit security group The Shadowserver Foundation stated that Sality remains a dangerous vector of entry into a large number of organizations.

5 sources

Reuters
Russian cybercrime operation being dismantled after two decades, US officials and CrowdStrike say | Reuters
View source article
CoinDesk
Russian malware that secretly stole BTC, ETH for 8 years gets dismantled by CrowdStrike and federal authorities
View source article
Japantimes
Russian cybercrime operation being dismantled after two decades: U.S. and CrowdStrike
View source article
Thenextweb
CrowdStrike and the FBI are dismantling Sality after 23 years
View source article
Cointelegraph
US Officials Work with CrowdStrike to Fight Malware behind Crypto Theft
View source article

Story comments

Loading comments…

Related entities

RussiaUnited States

Topics

Crypto privacy & surveillanceCybercrimeCrypto securityCryptocurrency theft