“In practice, the operation targeted the data structure at the heart of every bot's network awareness: its peer list,” CrowdStrike Counter Adversary Operations team said — and then removed those peers until the botnet stopped working.
How CrowdStrike and international law enforcement isolated Sality
On Monday, CrowdStrike’s Counter Adversary Operations team, working with international law enforcement agencies and industry partners, executed a peer-to-peer sinkhole operation that disrupted Sality. The operation systematically isolated infected machines so they could no longer communicate with the criminal operator or receive payloads. By corrupting the botnet’s peer information and inserting sinkhole entries into peer lists, the team broke the network’s ability to carry out payload downloads and direct transfers, effectively fragmenting and neutralizing the P2P infrastructure.
Sality’s scope and EggJagger’s cryptocurrency theft
Sality has operated since 2003 — a 23-year run — and has infected more than 15,000 machines worldwide. Over its lifetime it distributed a wide range of malicious code, including tools for credential theft, spam distribution, proxy services, network exploitation and distributed denial-of-service attacks. For the past eight years, its primary payload has been EggJagger, a clipboard-monitoring tool that replaces copied cryptocurrency addresses with attacker-controlled addresses. CrowdStrike estimates the Sality operator stole at least $150,000 in cryptocurrency using EggJagger alone.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageTechnical mechanics: peer lists, super peers, and 40-minute checks
Sality’s peer-to-peer architecture rests on each bot maintaining a list of known super peers — publicly reachable infected machines that form the backbone of the P2P network. Every 40 minutes, bots check whether their listed peers are still online and purge peers that fail to respond. The takedown took advantage of that behavior: operators of the disruption removed legitimate super peers from bots’ peer lists and replaced entries with purpose-built sinkholes. As more peers were purged and sinkhole entries propagated, infected machines became continuously isolated and the botnet’s command-and-control and payload-distribution capabilities were interrupted.
Domain seizures and cross-border action in the US and Europe
Alongside the sinkhole operation, US authorities moved to seize infrastructure linked to Sality. The US Justice Department, the FBI, and the Department of Defense Office of Inspector General’s Defense Criminal Investigative Service seized Sality-linked domains in the United States. International law enforcement in Bulgaria, Hungary and Romania also took action against additional Sality-linked domains hosted in Europe. Those domain seizures complemented the peer-list poisoning by removing additional avenues for the operator to coordinate or host resources.
Shadowserver, ISPs, and CSIRTs: identifying infections and notifying victims
The Shadowserver Foundation is coordinating the follow-up work with internet service providers and Computer Security Incident Response Teams (CSIRTs). Shadowserver is identifying infected systems and assisting in victim notification and remediation. The sinkhole approach provided police and cyber operatives with operational visibility into the botnet’s topology and progress of the disruption, enabling targeted notification efforts that feed into remediation by network operators and incident responders.
What this means for security teams, victims, and law enforcement
- Security teams and incident responders: The sinkholing removed the botnet’s ability to deliver or update payloads, but the infected endpoints remain — responders will rely on the visibility generated by the operation and coordination from Shadowserver, ISPs and CSIRTs to locate and remediate compromised machines.
- Victims and organizations with infected devices: With more than 15,000 machines implicated, affected parties should expect notifications routed through CSIRTs and ISPs; remediation will be the next practical step after identification.
- Law enforcement and prosecutors: The operation combined technical disruption with legal action — domain seizures in the US and coordinated actions in Bulgaria, Hungary and Romania — demonstrating a blended approach that couples sinkholing with takedowns of supporting infrastructure.
The operation removed the operator’s live communications and inserted sinkholes that give defenders visibility, but it also shifts the work to remediation and notification: identifying the more than 15,000 infected machines and ensuring they are cleaned. The combined tactical (peer-list poisoning) and legal (domain seizures) measures represent a multi-pronged disruption that, for now, has stopped Sality’s ability to push new payloads and siphon cryptocurrency via EggJagger, a theft CrowdStrike estimates at a minimum of $150,000.




