U.S. authorities and CrowdStrike disrupt the Sality botnet in an international cyber operation

U.S. and CrowdStrike Disrupt 23-Year-Old Sality Botnet in Global Takedown

U.S. authorities and cybersecurity company CrowdStrike have disrupted Sality, a long-running cybercrime botnet that has been operating since 2003, in a coordinated international operation targeting its infrastructure.

The operation involved the U.S. Department of Justice, FBI, the Defense Criminal Investigative Service, CrowdStrike, the Shadowserver Foundation and law enforcement agencies in Europe.

Authorities seized Sality-linked domains in the United States, while agencies in Bulgaria, Hungary and Romania took action against additional infrastructure in Europe. At the same time, CrowdStrike carried out a technical operation designed to isolate infected computers from the criminal network controlling them.

The takedown is significant because Sality has survived for more than two decades and used a decentralized peer-to-peer architecture that made the botnet more difficult to dismantle.

What Is the Sality Botnet?

Sality is a malware family that turns compromised computers into part of a larger botnet.

A botnet is a network of computers infected with malicious software and controlled by a cybercriminal. The owners of those computers may have no idea that their devices are being used as part of an attack infrastructure.

According to the U.S. Department of Justice, Sality has been active since 2003 and infected computers have been used in cyberattacks and cryptocurrency theft affecting victims in the United States and other countries.

CrowdStrike said the Sality infrastructure had distributed malicious payloads to more than 15,000 infected machines worldwide.

The long lifespan of the operation highlights how older malware can continue to pose a threat when its underlying infrastructure remains resilient.

Why Sality Was Difficult to Shut Down

One of Sality's most important characteristics was its peer-to-peer, or P2P, architecture.

Traditional botnets may rely heavily on centralized command-and-control servers. If investigators identify and take those servers offline, the criminal network can potentially be disrupted.

Sality worked differently.

Its infected computers could communicate with one another through a decentralized network. This made the infrastructure harder to attack because there was no single central point that could simply be switched off.

CrowdStrike said the network was specifically designed to be resilient and resistant to disruption. The company's researchers therefore had to analyze how the P2P system maintained its network of infected machines before developing a way to interfere with it.

How CrowdStrike Disrupted the Botnet

The technical operation used a peer-to-peer sinkhole to isolate infected machines.

Rather than trying to remove malware from every computer individually, researchers targeted the communication structure that allowed Sality's infected machines to remain connected to the criminal operator.

CrowdStrike said its operation manipulated the peer lists maintained by Sality's infected machines.

Legitimate peers were progressively removed from those lists, while specially designed sinkhole entries were introduced. As infected machines lost access to legitimate members of the criminal network, they became isolated from the operator.

Once isolated, the machines could no longer receive new tasking from the Sality operator through the disrupted network.

This approach effectively used Sality's own decentralized architecture against it.

U.S. Authorities Seized Sality-Linked Domains

The technical disruption was accompanied by legal and law-enforcement action.

The U.S. Department of Justice, FBI and Defense Criminal Investigative Service seized Sality-linked domains in the United States.

Law enforcement agencies in Bulgaria, Hungary and Romania also took action against Sality-related domains hosted in Europe.

The Shadowserver Foundation is working with internet service providers and computer security response teams to identify infected systems and assist with victim notification and remediation.

The international nature of the operation reflects the way modern cybercrime infrastructure operates across multiple jurisdictions.

A criminal network can have operators in one country, compromised computers in many other countries and supporting infrastructure hosted somewhere else.

What Was Sality Used For?

Sality was associated with several malicious activities.

According to U.S. authorities and cybersecurity researchers, the botnet was used to support activities including spam, distributed denial-of-service attacks, malware distribution and cryptocurrency theft.

Its infected machines could effectively become resources controlled by the criminal operator.

That meant a victim's computer could be used without the owner's knowledge to participate in broader cybercrime activity.

The cryptocurrency component is particularly notable because malware associated with Sality has been used to target cryptocurrency transactions.

The threat demonstrates how an apparently ordinary compromised computer can become part of a larger financial crime operation.

The Threat Did Not Disappear Overnight

Although authorities and CrowdStrike have significantly disrupted Sality's infrastructure, the operation does not necessarily mean that every previously infected computer has been cleaned.

A takedown can disconnect infected machines from their criminal controller while malware may still remain on individual systems.

This distinction is important for organizations and users that may have been exposed to Sality.

Security teams can use information from the disruption operation to identify potentially infected systems and begin remediation.

The Shadowserver Foundation is also assisting with identifying infections and supporting notification efforts.

Why the Sality Takedown Matters

The operation offers an important lesson for the broader cybersecurity industry.

Sality is more than two decades old, yet it remained capable of supporting criminal activity.

That shows that cybersecurity threats do not necessarily disappear simply because the malware behind them is old.

Criminal groups can continue using established infrastructure when it remains effective, difficult to detect or expensive to dismantle.

The operation also demonstrates the growing importance of cooperation between governments and private cybersecurity companies.

Law enforcement can use legal authority to seize domains and infrastructure, while security companies can provide technical intelligence and capabilities needed to disrupt complex networks.

In the Sality operation, those capabilities were combined into a coordinated international effort.

Could Sality Return?

It is too early to say whether the Sality network will remain permanently disrupted.

The person or group behind the operation has not been publicly identified, according to Reuters reporting.

Cybersecurity researchers will be watching closely for any attempt to rebuild the network or establish new infrastructure.

Because Sality's architecture was designed for resilience, rebuilding parts of the operation could theoretically be possible.

However, the seizure of domains and the disruption of the peer-to-peer communication system represent a major setback for the existing infrastructure.

What Users Can Do to Stay Safe

The Sality takedown also provides a reminder that basic cybersecurity practices remain important.

Users should keep operating systems, browsers and security software updated and avoid downloading software from unknown sources.

Suspicious email attachments and unexpected links should also be treated carefully.

Businesses should monitor endpoints for unusual network activity and maintain effective incident-response procedures.

Organizations that suspect a device has been compromised should isolate it from the network and investigate it rather than assuming that removing one suspicious file is enough.

For people who use cryptocurrency, transaction details should be checked carefully before funds are sent, particularly when addresses are copied and pasted.

A Major Setback for a Long-Running Botnet

The disruption of Sality marks a significant international cybersecurity operation against one of the longest-running botnets still relevant to modern cybercrime.

The network's history shows how difficult it can be to eliminate decentralized malicious infrastructure.

By combining domain seizures, international law enforcement cooperation and a technical P2P sinkhole operation, authorities and cybersecurity researchers were able to cut the existing Sality network off from its operator.

The next challenge will be determining how many systems remain infected and whether the criminals behind the operation attempt to rebuild their infrastructure.

For cybersecurity defenders, the Sality case provides another reminder that old threats can remain dangerous when they evolve and adapt.

Source: U.S. Department of Justice, CrowdStrike and Reuters reporting.

Frequently Asked Questions

What is the Sality botnet?

Sality is a long-running malware and botnet operation first identified in 2003. It infected computers and connected them through a peer-to-peer network that could be used for criminal activities.

How many computers did Sality infect?

CrowdStrike said Sality had distributed malicious payloads to more than 15,000 infected machines worldwide.

Who disrupted the Sality botnet?

The operation involved the U.S. Department of Justice, FBI, Defense Criminal Investigative Service, CrowdStrike, the Shadowserver Foundation and law enforcement agencies in Bulgaria, Hungary and Romania, with support from Europol and Eurojust.

What was Sality used for?

Sality was associated with activities including spam, DDoS attacks, malware distribution and cryptocurrency theft.

Why was Sality difficult to take down?

Sality used a decentralized peer-to-peer architecture, allowing infected computers to communicate with one another rather than relying entirely on a single central server.

Does the takedown mean all infected computers are clean?

No. Disrupting the criminal network can isolate infected computers, but it does not automatically remove malware from every affected device.

Could the Sality botnet come back?

Researchers will monitor the situation for attempts to rebuild the network or establish new infrastructure. The operator behind Sality has not been publicly identified.