A Long-Running Cybercrime Operation Bites the Dust: Sality Botnet Infrastructure Dismantled in Global Takedown
International law enforcement agencies and private partners have dealt a significant blow to cybercrime, dismantling the infrastructure of the notorious Sality botnet in a joint global operation. The takedown, which involved the seizure of malware-linked domains in several countries, marks a major victory for those fighting against online threats.
The Sality botnet has been a persistent presence on the internet for over two decades, infecting more than 15,000 devices with malware since its emergence in 2003. Controlled by a group tracked as SALTY SPIDER, likely based in Russia’s Republic of Bashkortostan, the botnet was used to distribute a wide range of malware families, including those designed for credential theft, spam distribution, and distributed denial-of-service (DDoS) attacks.
For the past eight years, Sality primarily pushed EggJagger malware payloads, which were used in clipjacking attacks. These malicious operations monitored victims’ clipboard data, replacing cryptocurrency wallet addresses with those controlled by the botnet operator. The botnet’s peer-to-peer (P2P) network structure allowed it to remain operational for so long, with infected machines communicating directly with each other.
The takedown effort involved a coordinated approach, with law enforcement agencies in several countries working together to seize Sality-linked domains and disrupt its communication channels. CrowdStrike’s Counter Adversary Operations team played a crucial role in dismantling the botnet by sinkholing its list of known super peers – essentially blocking the flow of malware between infected machines.
This operation is part of a larger trend of international law enforcement agencies taking down cybercrime operations worldwide. In recent months, authorities have disrupted multiple other significant cybercrime networks, including SocksEscort and Command and Control (C2) infrastructure used by several botnets.
The takedown of the Sality botnet serves as a reminder that law enforcement agencies and private partners are working together to combat online threats. While this operation is a significant success, it’s essential for individuals and organizations to remain vigilant against future attacks. By staying informed about cybersecurity risks and taking proactive measures to protect themselves, people can help prevent their devices from becoming part of the next botnet.
To stay safe online, users should ensure that their software and systems are up-to-date, use strong passwords and enable two-factor authentication whenever possible, and be cautious when clicking on links or downloading attachments. By being aware of these simple precautions, individuals can significantly reduce their risk of falling victim to malware attacks like those carried out by the Sality botnet.
Source: Bleeping Computer — 2026-09-02