Who acted and what they seized
In a coordinated international operation, U.S. federal agencies and European partners moved to dismantle the long-running Sality botnet infrastructure. The U.S. Department of Justice (DOJ), the FBI, and the Defense Criminal Investigative Service (DCIS) seized Sality-linked domains in the United States. Law enforcement partners in Bulgaria, Hungary, and Romania seized additional Sality-linked domains hosted in Europe. CrowdStrike's Counter Adversary Operations team participated alongside those public partners, contributing a technical sinkhole operation.
CrowdStrike sinkhole: how the peer-to-peer backbone was neutralized
CrowdStrike said it conducted a peer-to-peer sinkhole operation that dismantled Sality's control channels and isolated infected machines. The company described sinkholing the botnet's list of known super peers — the nodes that form Sality's communication backbone — in order to block two core propagation mechanisms: file packs (which perform direct payload transfers) and URL packs (which deliver payload download instructions). CrowdStrike concluded the operation "is now no longer under the operator's control."

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildSality's longevity and the malware it distributed
Sality has been active for more than two decades and, according to CrowdStrike, has infected over 15,000 devices with malware since at least 2003, when it first surfaced. CrowdStrike tracks the controlling criminal group as SALTY SPIDER, which it says is likely operating out of the Republic of Bashkortostan in Russia.
Across its history, Sality distributed a broad array of malware families, including tools for credential theft, spam distribution, proxy services, network exploitation, and distributed denial-of-service (DDoS) attacks. For the past eight years, however, CrowdStrike said the botnet's primary payload has been EggJagger. The company described EggJagger as a clipjacking tool that monitors the clipboard for cryptocurrency wallet addresses and silently replaces them with addresses controlled by the operator. At the time of the takedown, two separate Sality botnet networks remained active and were mainly used to push EggJagger payloads in clipjacking attacks.
This action in the context of other 2026 takedowns
The Sality disruption is the latest in a series of joint operations targeting large-scale cybercrime infrastructure this year. In March, American and European authorities, together with private partners, disrupted the SocksEscort cybercrime proxy network and took down command-and-control infrastructure used by the Aisuru, KimWolf, JackSkid, and Mossad botnets. Dutch authorities took a massive botnet of 17 million devices offline in May. Separately, an FBI-led operation disrupted the QScan and QTRouter hacking platforms used by Chinese cyber-espionage groups. Those actions, like the Sality takedown, combined law enforcement seizures and private-sector technical measures.
What this means for technologists, policymakers, and affected users
- Technologists and security teams: Expect to see remnants of peer-to-peer peer lists and URL/file pack references in forensic traces. The sinkholing of super peers is intended to block further propagation and prompt infected endpoints to purge peer lists, but responders will still need to identify and clean compromised hosts.
- Policymakers and law enforcement planners: The operation reinforces a playbook that blends domain seizures with industry sinkholing to neutralize P2P botnet control channels across jurisdictions. Coordination across the DOJ, FBI, DCIS, and European law enforcement was central to the domain takedowns in the U.S., Bulgaria, Hungary, and Romania.
- Affected enterprises and end users: Devices infected with Sality historically became part of a botnet used for varied criminal purposes; owners should assume compromise persisted until hosts are explicitly remediated, even though control has been disrupted externally.
After more than twenty years of continuous operation, the Sality botnet’s disruption demonstrates both the longevity of some criminal infrastructures and the reach of coordinated technical-and-legal countermeasures. CrowdStrike and the cooperating law enforcement agencies describe the network as no longer under the operator's control; the remaining work will be forensic cleanup of infected machines and monitoring for actor adaptation, as prior disruptions this year show adversaries and infrastructure can reconstitute in new forms.




