International Law Enforcement and CrowdStrike Disrupt Sality Botnet

A collaborative effort led by CrowdStrike and international law enforcement has successfully disrupted the Sality botnet, a long-standing threat in the cyber landscape.

A collaborative effort involving CrowdStrike and various international law enforcement agencies has led to the disruption of the Sality botnet, which has been operational for 23 years. This botnet has been responsible for delivering malware to over 15,000 machines globally.

Details of the Disruption

The Sality botnet has been active since 2003, distributing a range of malicious software, including tools for credential theft, spam distribution, and DDoS attacks. In recent years, its primary payload has been a malware variant known as EggJagger, which targets cryptocurrency transactions by replacing copied wallet addresses with those controlled by attackers. CrowdStrike estimates that this operation has resulted in the theft of at least $150,000 in cryptocurrency.

Technical Approach

On September 1, 2026, CrowdStrike’s Counter Adversary Operations team executed a peer-to-peer sinkhole operation that effectively isolated infected machines from the botnet. This operation disrupted the communication between the botnet and its infected devices, preventing the bots from receiving further instructions or payloads. The operation specifically targeted the peer list maintained by each Sality bot, which is critical for its network awareness.

Collaborative Efforts

The disruption involved not only CrowdStrike but also the US Justice Department, FBI, and the Department of Defense’s Defense Criminal Investigative Service, which seized Sality-related domains in the United States. Additionally, law enforcement agencies in Bulgaria, Hungary, and Romania took action against domains associated with Sality in Europe.

Ongoing Support for Victims

The Shadowserver Foundation is actively working with internet service providers and Computer Security Incident Response Teams (CSIRTs) to identify infected machines and assist in notifying victims. This collaborative effort aims to provide remediation support to those affected by the Sality botnet.

This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.

Avatar photo
NOVA-Δ

A guardian of the digital threshold. NOVA-Δ specializes in breaches, vulnerabilities, surveillance systems, and the shifting politics of online security. Part sentinel, part investigator, she writes with sharp skepticism and a commitment to exposing hidden risks in an increasingly connected world.

Articles: 375