Back to feed

US, Europe Disrupt Russia-Linked Sality Botnet After Two Decades

2 min
US, Europe Disrupt Russia-Linked Sality Botnet After Two Decades

This digest was compiled by AI from multiple sources — links to the originals are below.

US and European law enforcement, with CrowdStrike, disrupted the Russia-linked Sality peer-to-peer botnet on September 2, 2026. The operation sinkholed domains and isolated 15,000 infected machines worldwide. The botnet had operated since 2003 and stolen at least $150,000 in cryptocurrency.

Key Facts

  • The Sality botnet infected 15,000 machines worldwide and stole at least $150,000 in cryptocurrency.
  • US authorities seized Sality-linked domains, while police in Bulgaria, Hungary, and Romania took down malicious sites in Europe.
  • CrowdStrike attributes Sality to a criminal group tracked as Salty Spider, believed to operate from Bashkortostan, Russia, near the Kazakhstan border.
  • Since 2003, Sality maintained two independent peer-to-peer networks with incompatible protocol versions and different cryptographic keys.
  • For the past eight years, Sality's primary payload was EggJagger, a clipjacking tool that replaces cryptocurrency wallet addresses in the clipboard.

Operation Details

The US Department of Justice, FBI, and Defense Criminal Investigative Service seized Sality-linked domains in the United States. Police in Bulgaria, Hungary, and Romania took down malicious sites hosted in Europe. CrowdStrike and the non-profit Shadowserver Foundation provided technical support through a Europol program. The operation used sinkholing and protocol-level manipulation to isolate infected machines from the attacker's network. FBI Los Angeles Field Office Assistant Director Patrick Grandy said the collaboration enhances the FBI's cybersecurity capabilities.

Botnet Architecture and Persistence

Sality's peer-to-peer architecture allowed each node to communicate directly, creating a decentralized network without traditional command-and-control. The botnet persisted for over two decades because its P2P communication routed tasking among infected machines without a single point of failure. Sality regenerated continuously by attaching malware to executable files and spreading via network shares, removable drives, and file sharing. After gaining a foothold, Sality delivered additional payloads enabling credential theft, spam distribution, proxy services, network exploitation, and DDoS attacks. CrowdStrike's Counter Adversary Operations stated that with sufficient technical investment and coordination, even resilient criminal infrastructure can be dismantled.

Attribution and Payload

CrowdStrike tracks the Sality operators as Salty Spider, believed to be operating out of the Republic of Bashkortostan in Russia. Since 2003, the operator maintained two independent P2P networks sharing the same codebase but using incompatible protocol versions and different cryptographic keys. For the past eight years, the primary payload has been EggJagger, a clipjacking tool that monitors the clipboard for cryptocurrency wallet addresses. EggJagger silently replaces copied wallet addresses with addresses controlled by the operator.

1 source

Time · lag behind first