Decades-Old Sality Botnet Dismantled in Global Law Enforcement Operation
A coordinated international effort involving law enforcement and private cybersecurity partners has successfully disrupted the **Sality** peer-to-peer (P2P) botnet, which has been active for over two decades. The operation targeted the botnet's infrastructure, seizing domains and isolating infected machines to neutralize its long-running malicious activities.
International law enforcement agencies, in collaboration with private industry partners, have executed a significant operation to dismantle the **Sality** malware infrastructure. This joint action aimed to disrupt and take down the notorious P2P botnet, active since at least 2003.
Supported by **Europol** and **Eurojust**, the operation saw the **U.S. Department of Justice (DOJ)**, **FBI**, and **DCIS** seize **Sality**-linked domains within the United States. Concurrently, authorities in Bulgaria, Hungary, and Romania seized additional domains hosted in Europe.
**CrowdStrike**'s Counter Adversary Operations team played a pivotal role, collaborating with international law enforcement and private industry partners to dismantle the botnet's control channels. This was achieved through a peer-to-peer sinkhole operation that effectively isolated infected machines.
The **Sality** botnet has been a persistent threat for over two decades, infecting more than 15,000 devices. **CrowdStrike** attributes its control to a criminal group it tracks as **SALTY SPIDER**, believed to operate out of the Republic of Bashkortostan in Russia.
"The victim computers infected with **Sality** were part of a peer-to-peer (P2P) botnet, which is a network of computers (each a 'bot) infected with the **Sality** malware and controlled by the **Sality** operator," the **DOJ** stated.
At the time of the takedown, the two active **Sality** botnet networks were primarily used to deliver **EggJagger** malware payloads in clipjacking attacks. **EggJagger** is a tool that monitors the clipboard for cryptocurrency wallet addresses and silently replaces them with addresses controlled by the operator.

Throughout its history, **Sality** distributed a diverse range of malware families, including those involved in credential theft, spam distribution, proxy services, network exploitation, and distributed denial-of-service (DDoS) attacks.
The disruption was achieved by sinkholing **Sality**'s list of known super peers, which form its communication backbone. This action blocked file packs (direct payload transfers) and URL packs (payload download instructions) from propagating, effectively purging infected machines' peer lists.
"After more than two decades of continuous operation, **CrowdStrike**, together with international law enforcement and industry partners, conducted a successful disruption operation against the **Sality** botnet, which is now no longer under the operator's control," the cybersecurity company added.
This takedown is part of a broader trend of international law enforcement efforts against cybercrime. Earlier this year, American and European authorities disrupted the **SocksEscort** cybercrime proxy network and took down Command and Control (C2) infrastructure used by the **Aisuru**, **KimWolf**, **JackSkid**, and **Mossad** botnets. More recently, Dutch authorities neutralized a massive botnet of 17 million devices, and an **FBI**-led operation disrupted the **QScan** and **QTRouter** hacking platforms leveraged by Chinese cyber-espionage groups.