Global Crackdown Dismantles Sality Botnet, 11 Million Infected

Sality maintained two independent peer-to-peer networks that shared the same codebase, a design described as boosting resilience by avoiding a single central control point.
EggJagger, a wallet-copying tool used by the Sality operators, monitors copied cryptocurrency wallet addresses and covertly replaces them with attacker-controlled addresses to siphon funds.
Scale figures for Sality vary by source: authorities cite more than 11 million unique IP addresses and about 15,000 infected machines over its lifetime, while other reports describe as many as 1 million infected at peak.
The operation occurred around August 31–September 1, 2026, involving a multinational coalition (DOJ, FBI, DCIS, Bulgaria, Hungary, Romania) with private partners CrowdStrike and Shadowserver Foundation, plus Europol support.
CrowdStrike reports the Sality operation involved theft of at least 12.1 million rubles (~$150,000) over eight years, with peak stolen assets around $1.5 million in January 2025.
A global law-enforcement coalition has dismantled Sality, a Russia-linked botnet that infected millions of computers over 23 years. CircleID reports the operation, conducted around August 31, 2026, targeted a peer-to-peer network tied to more than 11 million unique IP addresses and roughly 15,000 infected machines. The takedown marks a major victory against one of the longest-running botnets, which stole cryptocurrency and distributed malware worldwide.
Authorities from the U.S., Bulgaria, Hungary, and Romania, working with Europol, CrowdStrike, and the Shadowserver Foundation, used sinkholing and network manipulation to cut off infected computers from criminal operators. CrowdStrike reports the scheme stole at least $150,000 over eight years, with peak stolen assets around $1.5 million in January 2025.
Sality emerged in 2003 as a worm that spread through infected USB drives and network shares. CircleID explains the botnet evolved into a sophisticated peer-to-peer network designed to survive without a central control point. The operators ran two independent P2P networks sharing the same codebase, making takedown far harder than traditional botnets with a single command server.
The botnet's decentralized design meant shutting it down required disrupting multiple communication pathways across infected hosts worldwide. Authorities used sinkholing — redirecting traffic to law-enforcement servers — and protocol-level manipulation to sever the connection between infected machines and operators, effectively paralyzing the network.
Sality operators used a tool called EggJagger to steal cryptocurrency from victims. The malware monitored users' copied wallet addresses and covertly swapped them with attacker-controlled addresses, siphoning funds without victims realizing the deception. This technique proved highly lucrative: CrowdStrike documented theft of at least 12.1 million rubles — roughly $150,000 — over eight years.
Peak criminal assets reached around $1.5 million in January 2025, just months before the takedown. The stolen funds were dispersed across cryptocurrency wallets, making recovery extremely difficult for law enforcement and victims alike.
The operation brought together the U.S. Department of Justice, FBI, Defense Criminal Investigative Service, and law-enforcement agencies from Bulgaria, Hungary, and Romania. Europol coordinated the international response, while private-sector partners CrowdStrike and the Shadowserver Foundation provided critical technical expertise to identify infected systems and map the botnet's infrastructure.
The scale of coordination underscores how modern botnets require international action to dismantle. No single country or company could have disrupted the distributed network alone. The success demonstrates growing capability to take down resilient malware that has survived for over two decades.
Sality's takedown highlights a persistent threat: peer-to-peer botnets are fundamentally harder to kill than centralized ones. Without a single point of failure, operators can rebuild faster. Infosecurity-Magazine notes that despite the August 31 disruption, residual infected machines may attempt to reconnect, requiring ongoing monitoring and intervention.
Authorities estimate up to 1 million machines were infected at Sality's peak, though current figures cited by law enforcement are lower. Many victims may remain unaware their computers were compromised, highlighting the need for broader cybersecurity awareness and regular system updates to prevent future infection.
Publishers
18
Articles
13
Reach
31