Close Menu

    Subscribe to Updates

    Get the latest creative news from infofortech

    What's Hot

    Is A Free VPN Worth Using? Here’s Why It Could Be Risky

    September 12, 2026

    Researchers link another hacking campaign to OpenAI agents

    September 12, 2026

    AI Agents Help Hackers Compromise 440 PaperCut Servers

    September 12, 2026
    Facebook X (Twitter) Instagram
    InfoForTech
    • Home
    • Latest in Tech
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    Facebook X (Twitter) Instagram
    InfoForTech
    Home»Cybersecurity»CrowdStrike Disrupts Sality Botnet After More Than 20 Years
    Cybersecurity

    CrowdStrike Disrupts Sality Botnet After More Than 20 Years

    InfoForTechBy InfoForTechSeptember 5, 2026No Comments4 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    After more than two decades online, one of the internet’s longest-running botnets has finally lost control of its infected machines.

    CrowdStrike said its Counter Adversary Operations team disrupted the Sality peer-to-peer (P2P) botnet on Aug. 31 in coordination with US and international law enforcement and industry partners. The operation effectively cut the alleged operator off from more than 15,000 infected systems worldwide.

    I’m at CrowdStrike’s conference this week and have gotten a firsthand look at how the operation came together, including details about the alleged operator that I cannot share here.

    What stood out to me was that this was not simply a CrowdStrike takedown.

    During a private fireside chat, Adam Meyers, senior vice president of Counter Adversary Operations at CrowdStrike, and Cristian Rodriguez, field CTO at CrowdStrike, repeatedly emphasized the community effort behind the disruption.

    Taking apart infrastructure that survived for more than 20 years required technical research, industry cooperation, and coordination across multiple law enforcement agencies.

    Sality survived without traditional command-and-control servers

    First observed in 2003, Sality evolved from file-infecting malware into a P2P botnet designed without the centralized command-and-control (C2) infrastructure defenders typically target.

    Infected systems communicated directly with one another. Sality also spread by attaching itself to executable files and moving through network shares, removable drives, and file-sharing systems. That combination made the botnet unusually difficult to eliminate.

    Sality’s main capability was the delivery of additional malware. More recently, the operator primarily distributed EggJagger, which monitors clipboards for cryptocurrency wallet addresses and replaces them with addresses controlled by the attacker.

    CrowdStrike estimates the operator stole at least 12.1 million Russian rubles, or roughly $150,000, in cryptocurrency through EggJagger alone.

    The botnet was also occasionally used for distributed denial-of-service (DDoS) attacks.

    One campaign targeted a Ukrainian forum on Feb. 25, 2022, one day after Russia launched its full-scale invasion of Ukraine. Other attacks targeted an Arabic-language financial forum and a Russian cryptocurrency exchange.

    Must-read security coverage

    CrowdStrike turned Sality’s P2P design against it

    The architecture that helped Sality survive ultimately gave defenders a way to dismantle it.

    Sality bots maintained lists of trusted “super peers” that served as the backbone of the network. However, the protocol did not authenticate those peers. A publicly reachable system that successfully completes the P2P handshake could effectively join the network.

    CrowdStrike and its partners exploited that weakness through peer-list manipulation.

    The operation progressively removed legitimate super peers from infected systems and replaced them with sinkhole infrastructure controlled by defenders.

    Machines behind firewalls or network address translation are isolated as they contact those sinkholes during their normal maintenance cycles.

    From the operator’s perspective, infected machines effectively disappear.

    CrowdStrike also worked with international law enforcement to take down URLs hosting Sality payloads, further limiting the botnet’s ability to deliver malware during the disruption and echoing previous efforts to disrupt major botnets.

    This operation involved the US Department of Justice, the FBI, the Defense Criminal Investigative Service, and the Shadowserver Foundation, with support from Europol, Eurojust, and law enforcement in Bulgaria, Hungary, and Romania.

    CrowdStrike said additional unnamed partners also contributed.

    Disruption does not mean infected systems are clean

    For security teams, there is an important distinction between disrupting Sality and removing it.

    The operation prevents the alleged operator from issuing new instructions through the botnet, but malware already running on infected systems does not simply disappear. CrowdStrike said infected machines now beacon to its sinkhole infrastructure, giving defenders another way to identify compromised systems.

    Organizations should use the indicators CrowdStrike published in their article alongside its research to search network and endpoint telemetry for infections. Any confirmed system still needs to be investigated and remediated.

    The larger lesson I took away from CrowdStrike this week is that disrupting cybercrime at this scale cannot happen in isolation. Sality survived changes in technology, security tools, and the threat landscape for more than 20 years.

    Breaking that infrastructure required defenders, researchers, industry partners, and law enforcement to work together against the same target. That idea came up repeatedly during my conversations at CrowdStrike’s conference this week.

    The team often pointed to the “Crowd” in CrowdStrike as representing the broader security community and argued that collaboration is one of the advantages defenders have when confronting threat actors. Sality is a good example of that in practice. For a botnet built around the strength of its peers, there is some irony in the fact that a different network of peers ultimately brought it down.

    Editor’s note: This article originally appeared on our sister publication, eSecurityPlanet.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    InfoForTech
    • Website

    Related Posts

    AI Agents Help Hackers Compromise 440 PaperCut Servers

    September 12, 2026

    Best Practices for Deception Technology Implementation

    September 12, 2026

    Weekly Update 521: Breach Perception v. Reality

    September 11, 2026

    Claude Used to Automate Exploitation and Data Theft Across Multiple Victims

    September 11, 2026

    180 Android Security Flaws Patched: What to Do

    September 11, 2026

    JADEPUFFER’s Second Wave Multi-Agent Attacks

    September 11, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026337 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202640 Views

    Mayiduo spent S$1M to produce his movie. It broke even & that’s a win in S’pore.

    March 31, 202628 Views

    How is Luckin Coffee expanding rapidly in S’pore while keeping its coffee so cheap?

    April 23, 202621 Views
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Advertisement
    About Us
    About Us

    Our mission is to deliver clear, reliable, and up-to-date information about the technologies shaping the modern world. We focus on breaking down complex topics into easy-to-understand insights for professionals, enthusiasts, and everyday readers alike.

    We're accepting new partnerships right now.

    Facebook X (Twitter) YouTube
    Most Popular

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026337 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202640 Views

    Mayiduo spent S$1M to produce his movie. It broke even & that’s a win in S’pore.

    March 31, 202628 Views
    Categories
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    • Latest in Tech
    © 2026 All Rights Reserved InfoForTech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.