Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
U.S. and CrowdStrike dismantle Sality botnet after 23 years of operation
00

U.S. and CrowdStrike dismantle Sality botnet after 23 years of operation

Sep 1, 2026

U.S. law enforcement and CrowdStrike have dismantled Sality, a Russian peer-to-peer botnet operating since 2003. Over 23 years, Sality evolved from sending spam to deploying the 'EggJagger' payload, which stole $150,000 by hijacking cryptocurrency clipboards. Exploiting a handshake vulnerability, CrowdStrike seeded the network with false data on August 31, 2026, isolating over 15,000 infected computers. The global operation involved domain seizures across the U.S. and Europe, though no arrests have been made.

Sality botnet takedown operation

  • ▪CrowdStrike began the technical dismantling of the Sality botnet on August 31, 2026, during a live demonstration at the company's Day Zero threat intelligence summit in Las Vegas.
  • ▪U.S. law enforcement and the cybersecurity firm CrowdStrike announced on September 1, 2026, the dismantling of Sality, a Russian cybercriminal botnet operation.

Peer-to-peer botnet architecture

  • ▪The Sality malware spread by attaching itself to executable files and programs shared over network drives and removable USB drives.
  • ▪The Sality botnet operated using a peer-to-peer architecture without a central server, with infected machines communicating directly with each other every 40 minutes.

EggJagger cryptocurrency clipboard theft

  • ▪CrowdStrike estimated that Sality's operators stole at least 12.1 million rubles, or approximately $150,000, over eight years using the EggJagger clipjacking payload.
  • ▪CrowdStrike tracks the Sality operator as SALTY SPIDER, who launched a denial-of-service attack in September 2023 against the Russian cryptocurrency exchange AvanChange.
  • ▪For its final eight years of operation, Sality's primary payload was EggJagger, a clipjacking tool that monitored clipboards for cryptocurrency wallet addresses and replaced them with the attacker's address.
  • ▪The stolen cryptocurrency from Sality's operations was largely left unspent, with the portfolio's value peaking at approximately 147 million rubles, or $1.35 million, in January 2025.

CrowdStrike reverse-engineering technique

  • ▪CrowdStrike seeded the Sality network with false information, replacing legitimate peer addresses with its own sinkhole servers to isolate more than 15,000 infected machines worldwide.
  • ▪CrowdStrike researcher Tillmann Werner stated that reverse-engineering Sality's structure and building the infrastructure to knock it down was the most complex botnet takeover the company had ever executed.
  • ▪CrowdStrike reverse-engineered Sality and exploited a security flaw where infected bots accepted any reachable machine that answered a handshake correctly without identity checks.

International law enforcement coordination

  • ▪The nonprofit security group The Shadowserver Foundation participated in the Sality takedown and worked with internet service providers to notify affected victims.
  • ▪The Sality takedown involved international coordination between the U.S. FBI, the U.S. Justice Department, the Defense Criminal Investigative Service, and law enforcement in Bulgaria, Hungary, and Romania.
  • ▪U.S. authorities seized Sality-linked web domains in the United States, while police in Bulgaria, Hungary, and Romania seized domains in Europe to disrupt the botnet's infrastructure.

Twenty-three year operation longevity

  • ▪No arrests have been announced in connection with the Sality takedown, and the operators, believed by the U.S. Justice Department to be based in Russia, remain publicly unidentified.
  • ▪Before deploying the EggJagger payload, Sality was used to send spam, launch distributed denial-of-service attacks, and deliver credential theft tools.
  • ▪First detected in 2003, Sality operated for 23 years, making it one of the internet's longest-running cybercriminal enterprises.

5 sources

Coindesk
Russian malware that secretly stole BTC, ETH for 8 years gets dismantled by CrowdStrike and federal authorities
View source article
Thenextweb
CrowdStrike and the FBI are dismantling Sality after 23 years
View source article
Decrypt
Sality Botnet Dismantled After Eight Years of Stealing Bitcoin and Ethereum - Decrypt
View source article
Japantimes
Russian cybercrime operation being dismantled after two decades: U.S. and CrowdStrike
View source article
Reuters
Russian cybercrime operation being dismantled after two decades, US officials and CrowdStrike say | Reuters
View source article

Story comments

Loading comments…

Related entities

Russia

Related Projects

Bitcoin

Topics

BitcoinCrypto securityEthereumCybercrimeRussiaCrypto privacy & surveillance