How Law Enforcement Finally Sank a 23-Year Botnet—and Why Its Peer-to-Peer Design Was Actually Its Undoing
2026-09-03Sality just got taken down. After 23 years of quietly stealing from infected machines—most recently through a clipboard-hijacking tool that swapped your wallet addresses for the operator's—law enforcement finally managed to pull the plug. The operation went live on August 31, 2026, announced September 1. It's one of those rare disruptions that actually feels like a win.
The cast was multinational. US authorities—the Department of Justice, FBI, Defense Criminal Investigative Service—worked with CrowdStrike and the Shadowserver Foundation. Bulgaria, Hungary, and Romania coordinated against their own infected infrastructure. The result: about 15,000 active machines in the botnet got cut off from their operator's control.
Here's what made Sality worth targeting now. For the last eight years, the malware deployed a tool called EggJagger. It sits on your clipboard. You copy a Bitcoin or Ethereum address. EggJagger spots it, replaces it with the operator's address instead. You paste. You send your money. You never knew what happened. CrowdStrike estimates it stole at least 12.1 million rubles—roughly $150,000—over that window. The stolen coins never moved. They piled up to about $1.5 million in peak value by January 2025.
The reason Sality lasted so long is the same reason it finally broke. Most botnets rely on central command servers. Kill the server, kill the botnet. Sality didn't bother. It used peer-to-peer communication instead. Infected machines talked directly to each other, spreading by attaching to files on network shares and USB sticks. Every 40 minutes they'd ping each other to stay connected. No traditional infrastructure to target. No central point of failure.
Except the protocol had a catastrophic vulnerability. Any machine that answered the handshake correctly got accepted as a peer. No cryptographic verification. No authentication. Nothing.
CrowdStrike's Counter Adversary Operations team saw that gap and drove a truck through it. They built their own servers, made them look like legitimate peers, and flooded the network with them. The criminal operator's real peer addresses got replaced with CrowdStrike sinkholes. Suddenly every infected machine was trying to talk to law enforcement instead of the bad guys. The operator lost the ability to send new commands. No way to push updated malware. The botnet got isolated.
Traditional tactics played their part too. The DOJ and FBI seized Sality domains in the US. International partners handled European-hosted domains. Shadowserver is now working with ISPs to identify victims and help clean up.
Sality's longevity shows why it mattered. Over 23 years it shifted payloads constantly—credential stealers, proxy services, spam distribution, network exploits, DDoS tools. Most people never knew their machines were compromised and actively working for someone else.
One catch: the operation shut down the operator's command channels but left the malware itself on infected systems. Until someone manually removes it, those machines stay vulnerable. The disruption ends the coordination. It doesn't end the infection. That part falls to victims and their service providers.
Source & further reading:
- Citi, Goldman, other global banks and asset managers team up on stablecoin venture — CoinDesk
- DOJ says Hamas crypto seizures reached $560,000 as FBI took over fundraising sites — CoinDesk
- Kraken parent Payward delays IPO to second quarter of 2027 at earliest — CoinDesk
- Crypto made new friends in U.S. primaries, but focus now shifts to general election — CoinDesk
- New Jersey becomes first state to ask Supreme Court to weigh in on prediction markets — CoinDesk
- Sality, one of the longest-running botnets, finally gets disrupted — The Record from Recorded Future News
- Central District of California | Sality Malware Disrupted in International Cyber Takedown — United States Department of Justice
- Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes — The Register
- Inside the Sality Botnet Disruption Operation — CrowdStrike
- Sality Botnet Dismantled After Eight Years of Stealing Bitcoin and Ethereum — Decrypt
- 23-Year-Old Sality P2P Botnet Disrupted — SecurityWeek
- Sality botnet infrastructure dismantled in joint global takedown — BleepingComputer
- US Officials Work with CrowdStrike to Fight Malware behind Crypto Theft — Cointelegraph
Sources
- Citi, Goldman, other global banks and asset managers team up on stablecoin venture
- DOJ says Hamas crypto seizures reached $560,000 as FBI took over fundraising sites
- Kraken parent Payward delays IPO to second quarter of 2027 at earliest
- Crypto made new friends in U.S. primaries, but focus now shifts to general election
- New Jersey becomes first state to ask Supreme Court to weigh in on prediction markets
- Sality, one of the longest-running botnets, finally gets disrupted
- Central District of California | Sality Malware Disrupted in International Cyber Takedown
- Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes
- Inside the Sality Botnet Disruption Operation
- Sality Botnet Dismantled After Eight Years of Stealing Bitcoin and Ethereum
- 23-Year-Old Sality P2P Botnet Disrupted
- Sality botnet infrastructure dismantled in joint global takedown
- US Officials Work with CrowdStrike to Fight Malware behind Crypto Theft