{"id":22660,"date":"2026-09-27T17:53:40","date_gmt":"2026-09-27T15:53:40","guid":{"rendered":"https:\/\/ig.technology\/index.php\/2026\/09\/27\/global-operation-disrupts-sality-botnet\/"},"modified":"2026-09-27T17:53:40","modified_gmt":"2026-09-27T15:53:40","slug":"global-operation-disrupts-sality-botnet","status":"publish","type":"post","link":"https:\/\/ig.technology\/index.php\/2026\/09\/27\/global-operation-disrupts-sality-botnet\/","title":{"rendered":"Global Operation Cuts Off Sality Botnet After 23 Years","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>A multinational law enforcement and cybersecurity operation has disrupted Sality, one of the internet\u2019s longest-running botnets, severing its operator\u2019s access to more than 33,000 infected computers worldwide. CrowdStrike said the coordinated action on August 31 isolated compromised devices from the criminal command channel, ending the operator\u2019s ability to issue new instructions through infrastructure that had remained active since 2003.<\/p>\n<p>The <a href=\"https:\/\/www.justice.gov\/usao-cdca\/pr\/sality-malware-disrupted-international-cyber-takedown\">U.S. Department of Justice<\/a> said authorities seized Sality-linked domains in the United States while law enforcement agencies in Bulgaria, Hungary, and Romania acted against additional domains in Europe. The effort also involved the FBI, the Defense Criminal Investigative Service, Europol, Eurojust, CrowdStrike and the Shadowserver Foundation, which is helping internet providers and incident-response teams identify victims and coordinate remediation.<\/p>\n<p>Sality survived for more than two decades largely because it used a decentralized peer-to-peer design instead of relying on a conventional command-and-control server. According to <a href=\"https:\/\/www.crowdstrike.com\/en-us\/blog\/inside-sality-botnet-disruption-operation\/\">CrowdStrike\u2019s technical account<\/a>, investigators turned that architecture against the botnet by manipulating the peer lists maintained by infected systems, removing legitimate criminal-controlled super peers and inserting defensive sinkhole nodes. Two active Sality networks, known as versions 3 and 4, used incompatible protocols and separate cryptographic keys but were attributed to the same operator.<\/p>\n<p>The malware functioned as a delivery platform for additional malicious code, supporting credential theft, spam, proxy services, network exploitation and distributed denial-of-service attacks. In recent years its main payload was EggJagger, a clipboard-hijacking tool that replaced copied cryptocurrency wallet addresses with addresses controlled by the attacker. CrowdStrike estimates that payload alone stole at least 12.1 million rubles, roughly $150,000, while other malware distributed through Sality generated additional revenue.<\/p>\n<p>The disruption blocks new tasking but does not remove malware already installed on victim systems. CrowdStrike said infected machines now contact defender-controlled sinkholes and urged organizations to examine endpoint and network telemetry, use the published indicators and detection rules, and clean confirmed infections. The Sality operator has not been publicly identified, leaving defenders to watch for attempts to rebuild the network or shift to new infrastructure.<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>A multinational operation has isolated more than 33,000 Sality-infected computers, ending the operator&#8217;s control of the 23-year-old botnet.<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":22659,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[131,130,132,129],"class_list":["post-22660","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cyber-security","tag-botnet","tag-crowdstrike","tag-cybercrime","tag-sality"],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/ig.technology\/index.php\/wp-json\/wp\/v2\/posts\/22660","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ig.technology\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ig.technology\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ig.technology\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/ig.technology\/index.php\/wp-json\/wp\/v2\/comments?post=22660"}],"version-history":[{"count":0,"href":"https:\/\/ig.technology\/index.php\/wp-json\/wp\/v2\/posts\/22660\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ig.technology\/index.php\/wp-json\/wp\/v2\/media\/22659"}],"wp:attachment":[{"href":"https:\/\/ig.technology\/index.php\/wp-json\/wp\/v2\/media?parent=22660"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ig.technology\/index.php\/wp-json\/wp\/v2\/categories?post=22660"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ig.technology\/index.php\/wp-json\/wp\/v2\/tags?post=22660"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}