International law enforcement agencies and cybersecurity companies have disrupted the Sality botnet, dismantling infrastructure behind one of the longest-running malware operations on the internet.
The coordinated takedown involved authorities in the United States and Europe, with support from Europol and Eurojust, alongside private-sector cybersecurity partners. Sality-linked domains were seized in the U.S., Bulgaria, Hungary, and Romania, while additional technical measures were used to break the botnet’s peer-to-peer communication channels.
Sality Botnet Disrupted Through International Operation
The U.S. Department of Justice, FBI, and Defense Criminal Investigative Service seized domains associated with Sality infrastructure in the United States. European authorities simultaneously targeted additional infrastructure hosted across multiple countries.
CrowdStrike’s Counter Adversary Operations team also worked with law enforcement and industry partners to conduct a peer-to-peer sinkhole operation, redirecting botnet communications away from attacker-controlled infrastructure and isolating infected systems.
Unlike traditional botnets that depend heavily on centralized command-and-control servers, Sality uses a P2P architecture, making disruption significantly more difficult because infected machines can communicate with one another directly.
Sality Operated for More Than Two Decades
Sality first appeared in the early 2000s and evolved into a persistent malware ecosystem capable of supporting multiple forms of cybercrime.
According to CrowdStrike, the botnet is associated with a threat group tracked as SALTY SPIDER. Over its lifetime, Sality has been used for a broad range of malicious activity, including:
- Credential theft
- Spam distribution
- Proxy services
- Network exploitation
- Distributed denial-of-service attacks
- Malware delivery
- Cryptocurrency theft
The botnet reportedly infected more than 15,000 devices over the course of its operation.
EggJagger Became Sality’s Primary Malware Payload
In recent years, Sality’s primary payload has been EggJagger, a malware tool used in clipjacking attacks.
Clipjacking malware monitors a victim’s clipboard for cryptocurrency wallet addresses. When a user copies a legitimate wallet address, the malware silently replaces it with an address controlled by the attacker.
This technique can redirect cryptocurrency payments without requiring the attacker to steal account credentials or compromise an exchange directly.
Because cryptocurrency addresses are long and difficult to verify manually, victims may not notice the substitution before completing a transaction.
P2P Sinkholing Cut Off Sality’s Control Channels
The disruption operation targeted Sality’s known super peers, which act as critical communication nodes within the botnet.
By sinkholing these systems, investigators were able to interfere with two important mechanisms used by the malware:
- File packs, which distribute malicious payloads directly between infected systems.
- URL packs, which provide infected devices with instructions for downloading additional malware.
The operation also disrupted peer-list propagation, reducing the ability of infected devices to discover and communicate with other nodes inside the Sality network.
This approach effectively separated compromised systems from the infrastructure used by botnet operators to distribute new commands and malware.
Why the Sality Takedown Matters
The operation demonstrates how international cooperation and private-sector threat intelligence can be used to dismantle resilient peer-to-peer botnets that are specifically designed to survive server seizures.
Sality’s long operational history also highlights the persistence of legacy malware ecosystems. Even malware families first observed decades ago can remain effective when operators continuously update infrastructure, delivery mechanisms, and monetization strategies.
For defenders, the takedown reinforces the importance of endpoint monitoring, network traffic analysis, threat intelligence integration, and rapid remediation of infected hosts. Organizations should also monitor for suspicious cryptocurrency clipboard activity, anomalous peer-to-peer communications, and malware persistence mechanisms associated with long-running botnet families.

Leave a Reply