Press play to start listening
On August 31, US and European authorities, working with CrowdStrike and the Shadowserver Foundation, disrupted the Sality botnet, a peer-to-peer (P2P) network that had operated for more than two decades. The operation cut infected Windows computers off from the operator’s command channel.
The US-led operation involved the Department of Justice (DOJ), FBI, Defense Criminal Investigative Service (DCIS), and law enforcement agencies in Bulgaria, Hungary and Romania.
On the other hand, CrowdStrike carried out the P2P sinkholing, while the Shadowserver Foundation is working with internet service providers and Computer Security Incident Response Teams to identify infections and notify victims. Europol and Eurojust supported the operation.
Europol said in its September 2 press release that the Sality botnet, first observed in 2003, had been linked to more than 11 million unique IP addresses over its lifetime. This does not mean 11 million computers were infected simultaneously. At its peak, the operator had access to as many as one million infected machines.
CrowdStrike also documented DDoS attacks on forex2030(.)com, an Arabic-language website, in 2016 and kharkovforum(.)com, a Ukrainian forum hosting discussions about Russia’s invasion of Ukraine, in 2022.
How Sality Spread and Operated
Sality infected Windows executable files and spread when those files were copied through network shares, removable drives and file-sharing systems. Its main technical function was delivering additional malware used for credential theft, spam distribution, proxy services, network exploitation and DDoS attacks. Its self-spreading design did not depend on phishing campaigns, exploit kits or continued action from the operator.
For the eight years before the disruption, Sality’s primary payload was EggJagger, a clipjacking tool that monitored victims’ clipboards for Bitcoin and Ethereum wallet addresses and replaced them with addresses controlled by the operator.
CrowdStrike estimates that the tool stole at least 12.1 million Russian rubles, around $150,000. The value of the operator’s unspent cryptocurrency portfolio peaked at approximately 147 million rubles in January 2025. CrowdStrike tracks the suspected operator as SALTY SPIDER and assesses that the group likely operates from Russia’s Republic of Bashkortostan.
Disruption Details
Sality’s P2P design was one of the reasons it survived for so long. Unlike a traditional botnet that relies on a central server, Sality’s infected computers could communicate through the P2P network. That made it harder to take down, but investigators eventually found a way to use the same system against it.
CrowdStrike used P2P sinkholing to isolate infected computers by manipulating Sality’s peer lists. Every 40 minutes, infected machines checked whether their known “super peers” were still online. The researchers used this process to invalidate legitimate peers and insert sinkhole servers into the lists, gradually cutting infected machines off from the operator’s network.
The US DOJ noted that the operation involved the seizure of Sality-linked domains in the United States, while authorities in Bulgaria, Hungary and Romania acted against additional domains in Europe. The Shadowserver Foundation is helping identify infected systems and notify victims.
Although the operation prevents Sality’s operator from issuing new commands or distributing additional payloads, it does not remove Sality or other malware already installed on infected computers. Those systems still require remediation.

