CrowdStrike and US law enforcement have disrupted the Sality botnet, a Russian cybercrime operation active since 2003, in an international operation launched on Monday that cut infected computers off from their operator and seized domains used to distribute malware.
The operation involved the US Department of Justice, FBI and Department of Defense Office of Inspector General’s Defense Criminal Investigative Service, alongside law enforcement agencies in Bulgaria, Hungary and Romania. Europol, Eurojust and the Shadowserver Foundation supported the effort, which targeted Sality’s infrastructure in the US and Europe.
According to the Justice Department, Sality malware has infected computers since 2003, allowing its operator to steal cryptocurrency and conduct cyberattacks against victims in the US and elsewhere. The peer-to-peer botnet allowed compromised machines to communicate directly, avoiding the single command-and-control server that can provide a conventional botnet with a point of failure.
CrowdStrike said its Counter Adversary Operations team used a peer-to-peer sinkhole operation to exploit weaknesses in Sality’s network architecture. The operation manipulated the botnet’s lists of trusted peers, replacing legitimate infrastructure with sinkhole systems and preventing infected machines from receiving new instructions.
CrowdStrike researcher Tillmann Werner told Reuters that the operation had required extensive reverse engineering and infrastructure development. “This was the most complex botnet takeover we have ever done,” Werner said, describing Sality as designed to withstand attempts to disrupt or take control of it.
CrowdStrike estimated that Sality had distributed malicious payloads to more than 15,000 infected machines worldwide. Its primary payload over the past eight years was EggJagger, which monitored cryptocurrency wallet addresses copied to the clipboard and replaced them with addresses controlled by the operator; CrowdStrike estimated at least ₽12.1 million, or about $150,000, had been stolen through the technique.
The US authorities seized Sality-linked domains in the country, while authorities in Bulgaria, Hungary and Romania took action against additional domains hosted in Europe. Shadowserver is working with internet service providers and computer security response teams to identify infections and support victim notification and remediation.
David Watson, director of the Shadowserver Foundation, told Reuters that despite its age, Sality remained a threat to organisations. “It’s still a vector into a lot of organisations,” Watson said, while noting that the next test would be whether its unidentified operator attempts to rebuild the network.
Existing infections remain active even after the disruption, CrowdStrike said, meaning organisations must remove the malware from affected systems rather than rely solely on the loss of its command infrastructure.


