CrowdStrike Disrupts Sality Botnet After More Than 20 Years

CrowdStrike and international partners disrupted the 20-year-old Sality botnet, cutting off its operator.

Written By
Ken Underhill
Ken Underhill
Sep 2, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

After more than two decades online, one of the internet’s longest-running botnets has finally lost control of its infected machines.

CrowdStrike said its Counter Adversary Operations team disrupted the Sality peer-to-peer (P2P) botnet on Aug. 31 in coordination with U.S. and international law enforcement and industry partners. 

The operation effectively cut the alleged operator off from more than 15,000 infected systems worldwide.

I’m at CrowdStrike’s conference this week and got a first-hand look at how the operation came together, including details about the alleged operator that I cannot share here.

What stood out to me was that this was not simply a CrowdStrike takedown.

During a private fireside chat, Adam Meyers, senior vice president of Counter Adversary Operations at CrowdStrike, and Cristian Rodriguez, field CTO at CrowdStrike, repeatedly emphasized the community effort behind the disruption. 

Taking apart infrastructure that survived for more than 20 years required technical research, industry cooperation, and coordination across multiple law enforcement agencies.

Sality survived without traditional command-and-control servers

First observed in 2003, Sality evolved from file-infecting malware into a P2P botnet designed without the centralized command-and-control (C2) infrastructure defenders typically target.

Infected systems communicated directly with one another. Sality also spread by attaching itself to executable files and moving through network shares, removable drives, and file-sharing systems.

That combination made the botnet unusually difficult to eliminate.

Sality’s main capability was delivering additional malware. More recently, the operator primarily distributed EggJagger, which monitors clipboards for cryptocurrency wallet addresses and replaces them with addresses controlled by the attacker.

CrowdStrike estimates the operator stole at least 12.1 million Russian rubles, or roughly $150,000, in cryptocurrency through EggJagger alone.

The botnet was also occasionally used for distributed denial-of-service (DDoS) attacks

Advertisement

One campaign targeted a Ukrainian forum on Feb. 25, 2022, one day after Russia launched its full-scale invasion of Ukraine. Other attacks targeted an Arabic-language financial forum and a Russian cryptocurrency exchange.

CrowdStrike turned Sality’s P2P design against it

The architecture that helped Sality survive ultimately gave defenders a way to dismantle it.

Sality bots maintained lists of trusted “super peers” that served as the backbone of the network. However, the protocol did not authenticate those peers. A publicly reachable system that completed the correct P2P handshake could effectively join the network.

CrowdStrike and its partners exploited that weakness through peer-list manipulation.

The operation progressively removed legitimate super peers from infected systems and replaced them with sinkhole infrastructure controlled by defenders. 

Machines behind firewalls or network address translation are isolated as they contact those sinkholes during their normal maintenance cycles.

From the operator’s perspective, infected machines effectively disappear.

CrowdStrike also worked with international law enforcement to take down URLs hosting Sality payloads, further limiting the botnet’s ability to deliver malware during the disruption.

This operation involved the U.S. Department of Justice, FBI, Defense Criminal Investigative Service, and Shadowserver Foundation, with support from Europol, Eurojust, and law enforcement in Bulgaria, Hungary, and Romania. 

CrowdStrike said additional unnamed partners also contributed.

Disruption does not mean infected systems are clean

For security teams, there is an important distinction between disrupting Sality and removing it.

The operation prevents the alleged operator from issuing new instructions through the botnet, but malware already running on infected systems does not simply disappear.

CrowdStrike said infected machines now beacon to its sinkhole infrastructure, giving defenders another way to identify compromised systems. 

Organizations should use the indicators CrowdStrike published in their article alongside its research to search network and endpoint telemetry for infections.

Any confirmed system still needs to be investigated and remediated.

The larger lesson I took away from CrowdStrike this week is that disrupting cybercrime at this scale cannot happen in isolation. Sality survived changes in technology, security tools, and the threat landscape for more than 20 years.

Advertisement

Breaking that infrastructure required defenders, researchers, industry partners, and law enforcement to work together against the same target.

That idea came up repeatedly during my conversations at CrowdStrike’s conference this week. 

The team often pointed to the “Crowd” in CrowdStrike as representing the broader security community and argued that collaboration is one of the advantages defenders have when confronting threat actors.

Sality is a good example of that in practice. 

For a botnet built around the strength of its peers, there is some irony in the fact that a different network of peers ultimately brought it down.

Ken Underhill

Ken Underhill is an award-winning cybersecurity professional, bestselling author, and seasoned IT professional. He holds a graduate degree in cybersecurity and information assurance from Western Governors University and brings years of hands-on experience to the field.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.