"From the operator’s perspective, infected machines simply disappear," CrowdStrike wrote, describing the trick it used to sever a 23‑year criminal operation that infected more than 11 million devices.
CrowdStrike's technical disruption
CrowdStrike said it played a crucial role in rendering Sality irrecoverable by dismantling the botnet’s technical infrastructure. Rather than attacking a central command server, the company targeted the botnet’s peer list — the set of infected machines each node used to find others — and "tricked the network into permanently cutting off access to those devices," CrowdStrike wrote. The result, according to the company, is that the network is no longer under the operator’s control.
International law enforcement and domain seizures
The takedown was a globally coordinated effort: Sality’s domains were seized with support from the FBI, the Justice Department and authorities from Europol, Bulgaria, Hungary and Romania, officials said. Europol characterized the action as the culmination of work by global law enforcement stretching back to 2017. Officials did not name the person or cybercrime group behind Sality.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleHow Sality's peer‑to‑peer design both hid and exposed it
Sality’s longevity — a reported 23 years of operation and infections on more than 11 million devices — flowed directly from its peer‑to‑peer architecture. The botnet used infected machines themselves to communicate, creating a decentralized structure that “made system‑wide disruption efforts more difficult,” CrowdStrike wrote. At the same time, the company argued those same properties provided an attack surface: by manipulating the peer lists, CrowdStrike says it induced infected machines to disappear from the network’s view, severing the operator’s control.
Shadowserver, ISPs, and remediation
The Shadowserver Foundation is working with internet service providers to identify devices infected by Sality and to aid remediation, the announcement said. That operational follow‑through complements the domain seizures and technical neutralization: while domains and control channels were seized or disrupted, Shadowserver’s coordination with ISPs is aimed at finding and cleaning the individual devices the botnet had relied on.
What this means for technologists, policymakers, and infected users
- Technologists and security teams: CrowdStrike’s account centers on a novel operational approach — manipulating a peer list rather than taking down a centralized server — which security teams will observe as a concrete tactic that worked against a long‑running peer‑to‑peer botnet.
- Policymakers and law enforcement: The multi‑national nature of seizures and Europol’s statement that the effort traces to 2017 underscore sustained cross‑border coordination involving the FBI and the Justice Department, highlighting how long investigations and legal actions may span for resilient infrastructures.
- Infected device owners and ISPs: Shadowserver’s work with ISPs to identify and remediate infected devices signals that owners of compromised machines should expect outreach and cleanup efforts tied to the takedown, as the operation moves from network disruption to device‑level remediation.
The authorities and private actors who joined the operation framed the result as decisive but partial. Justice Department statements tied Sality to cryptocurrency theft and cyberattacks targeting victims in the United States and abroad, and CrowdStrike characterized the operator as primarily financially motivated while also attributing three DDoS attacks to the botnet — suggesting intermittent use for personal or political aims. Bill Essayli, first assistant U.S. attorney, warned that "Cybercriminals, botnets, and malware are a clear and present danger to our nation’s security and economy."
At the same time, officials stopped short of naming the individual or group behind Sality. CrowdStrike summed up the broader message: "This operation demonstrates that peer‑to‑peer architecture, long considered a shield against disruption, is not invincible," and added, "Operating for decades without consequence does not mean operating without risk." What remains for investigators and defenders is to convert a technical neutralization and domain seizure into lasting remediation for the millions of devices Sality once counted as peers.




