Global Law Enforcement Dismantles Sality Botnet After Two Decades

Joint operation seizes domains and disrupts peer-to-peer malware network linked to cryptocurrency clipjacking

edit
By LineZotpaper
Published
Read Time2 min
International law enforcement agencies, led by the U.S. Department of Justice and the FBI, and supported by cybersecurity firm CrowdStrike, have seized domains and disrupted the peer-to-peer infrastructure of the Sality botnet, a malware network active since at least 2003 that infected over 15,000 devices globally.

In a coordinated international action, law enforcement agencies from the United States, Bulgaria, Hungary, and Romania, along with private industry partners, have targeted the Sality botnet. The U.S. Department of Justice (DOJ), FBI, and DCIS seized Sality-linked domains in the United States, while counterparts in Europe took down additional domains.

CrowdStrike's Counter Adversary Operations team played a key role by conducting a peer-to-peer sinkhole operation, isolating infected machines and blocking the botnet's control channels. According to the DOJ, the Sality botnet is a network of computers infected with the Sality malware and controlled by a single operator. CrowdStrike tracks the criminal group behind Sality as SALTY SPIDER, which is likely operating out of the Republic of Bashkortostan in Russia.

The takedown specifically targeted two Sality botnet networks that were still active. CrowdStrike stated that these networks were primarily used to push EggJagger malware payloads in clipjacking attacks. EggJagger monitors the clipboard for cryptocurrency wallet addresses and silently replaces them with addresses controlled by the operator. Over its long history, Sality has also been used for credential theft, spam distribution, proxy services, network exploitation, and distributed denial-of-service (DDoS) attacks.

The disruption was achieved by sinkholing Sality's list of known super peers, which form the botnet's communication backbone. This blocked file packs and URL packs from propagating and purged the peer lists of infected machines. CrowdStrike confirmed that the botnet is now no longer under the operator's control.

§

Analysis

Why This Matters

  • Disrupts a malware network that has operated with impunity for over 23 years, directly reducing the capacity for cryptocurrency theft via clipjacking.
  • Demonstrates the effectiveness of international law enforcement cooperation in tackling sophisticated, long-running cybercrime infrastructure.
  • Highlights the persistent threat of peer-to-peer botnets, which are harder to dismantle than centralized command-and-control networks.

Background

The Sality botnet first emerged in 2003 and evolved over two decades to become one of the most enduring malware threats. It operates using a peer-to-peer architecture, where infected machines communicate without a central command server, making traditional takedown methods difficult. The criminal group SALTY SPIDER, believed to be based in Russia, controlled the network. In recent years, the botnet's primary payload shifted to EggJagger, a clipjacking tool targeting cryptocurrency users. This operation is part of a broader pattern of international cybercrime crackdowns in 2026, including the dismantling of a proxy network in March.

Key Perspectives

Law Enforcement (DOJ, FBI, EU partners): Position the takedown as a victory against a long-standing cybercrime vector, protecting consumers and businesses from financial theft and network exploitation. CrowdStrike (Private industry partner): Emphasizes the technical complexity of disrupting a P2P botnet and the value of public-private collaboration in cyber defense. Critics/Skeptics: May question the long-term impact, as botnet operators could attempt to rebuild infrastructure or infected machines remain compromised. The inability to arrest the SALTY SPIDER group in Russia limits the operation's retributive effect.

What to Watch

  • Whether Sality infections decline measurably in the weeks following the sinkhole operation.
  • Any statements or evidence of the SALTY SPIDER group attempting to re-establish control or migrate to new malware.
  • Further coordinated law enforcement actions against other persistent botnets, which may follow this model of domain seizures and P2P disruption.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.