A Major Cybercrime Network Dismantled: Sality Botnet’s 23-Year Reign Comes to an End
In a significant blow to cybercrime, international law enforcement agencies and private partners have joined forces to dismantle the Sality botnet infrastructure in a joint global takedown. This operation marks a major milestone in the ongoing effort to disrupt and dismantle large-scale cybercrime networks that have plagued the internet for years.
The Sality botnet has been active since at least 2003, infecting over 15,000 devices with malware during its nearly two-decade reign. The botnet was controlled by a criminal group known as SALTY SPIDER, which is believed to be operating out of the Republic of Bashkortostan in Russia. The botnet’s primary payload has been EggJagger, a clipjacking tool that monitors and steals cryptocurrency wallet addresses.
The takedown operation involved the seizure of Sality-linked domains in the United States, Europe, Bulgaria, Hungary, and Romania. CrowdStrike, a leading cybersecurity company, played a key role in the disruption by sinkholing Sality’s list of known super peers, which form its communication backbone. This move effectively blocked file packs and URL packs from propagating, isolating infected machines from the botnet.
The P2P (peer-to-peer) structure of the botnet made it particularly difficult to disrupt. Infected computers were connected directly to each other, allowing the Sality operator to control them remotely. However, by identifying and disrupting the super peers, the takedown team was able to sever the communication channels between infected machines.
The dismantling of the Sality botnet is a significant victory for law enforcement agencies worldwide, which have been working together to disrupt and dismantle cybercrime networks. In recent months, similar operations have taken down other notable botnets, including the SocksEscort proxy network, the Aisuru, KimWolf, JackSkid, and Mossad botnets, as well as a massive botnet of 17 million devices.
For individuals and organizations, this takedown serves as a reminder of the importance of maintaining robust cybersecurity measures. While it’s impossible to prevent all cyber threats, being aware of the risks and taking proactive steps can significantly reduce the likelihood of falling victim to attacks. As seen in the case of Sality, once attackers gain access to a system using valid credentials, prevention measures often drop sharply.
In light of this operation, we advise readers to remain vigilant and take the following precautions:
* Regularly update your operating system and software to ensure you have the latest security patches.
* Use strong passwords and enable two-factor authentication whenever possible.
* Monitor your network for suspicious activity and report any anomalies to your IT department or law enforcement.
* Stay informed about emerging threats and vulnerabilities, and adjust your cybersecurity measures accordingly.
By staying ahead of cybercrime networks like Sality, we can reduce the risks associated with online activities and create a safer digital landscape.
Source: Bleeping Computer — 2026-09-02