Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Lords call for AI ‘kill switch’ powers in UK

    September 3, 2026

    Sality botnet infrastructure dismantled in joint global takedown

    September 3, 2026

    How stablecoins are quietly becoming the Fed’s debt buyer of last resort

    September 3, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Lords call for AI ‘kill switch’ powers in UK
    • Sality botnet infrastructure dismantled in joint global takedown
    • How stablecoins are quietly becoming the Fed’s debt buyer of last resort
    • The universe has plenty of hydrogen. So why is star formation collapsing?
    • Macron to hold first talks with UK’s Burnham after viewing Bayeux Tapestry in London
    • How Merkel and Merz lost eastern Germany to the AfD – POLITICO
    • MoD withheld information about nuclear test veterans’ records, ex-minister claims
    • Hands-on with Philips Hue’s new Liane 360° Rope Lights
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, September 3
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Sality botnet infrastructure dismantled in joint global takedown

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 3, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    International law enforcement agencies and private partners have seized Sality malware infrastructure in a joint action aiming to disrupt and take down the peer-to-peer (P2P) botnet.

    As part of this operation, supported by Europol and Eurojust, the U.S. Department of Justice (DOJ), FBI, and DCIS seized Sality-linked domains in the United States, while authorities in Bulgaria, Hungary, and Romania seized additional Sality-linked domains hosted in Europe.

    CrowdStrike’s Counter Adversary Operations team, in collaboration with international law enforcement and private industry partners, also dismantled the botnet’s control channels in a peer-to-peer sinkhole operation that isolated infected machines.

    The Sality botnet has been active for more than two decades and has infected over 15,000 devices with malware since at least 2003, when it first surfaced. CrowdStrike says Sality is controlled by a criminal group it tracks as SALTY SPIDER, which is likely operating out of the Republic of Bashkortostan in Russia.

    “The victim computers infected with Sality were part of a peer-to-peer (P2P) botnet, which is a network of computers (each a ‘bot) infected with the Sality malware and controlled by the Sality operator,” the DOJ said.

    According to CrowdStrike, the two separate Sality botnet networks that were still active when the takedown took place this week were mainly used to push EggJagger malware payloads in clipjacking attacks.

    “Throughout its history, Sality distributed a wide variety of distinct malware families spanning credential theft, spam distribution, proxy services, network exploitation, and distributed denial-of-service (DDoS) attacks,” CrowdStrike said. “For the past eight years, the primary payload has been EggJagger, a clipjacking tool that monitors the clipboard for cryptocurrency wallet addresses and silently replaces them with addresses controlled by the operator.”

    Sality infected devices
    Sality infected devices (CrowdStrike)

    ​The P2P botnet was disrupted by sinkholing Sality’s list of known super peers, which form its communication backbone, to block file packs (direct payload transfers) and URL packs (payload download instructions) from propagating and purging infected machines’ peer lists.

    “After more than two decades of continuous operation, CrowdStrike, together with international law enforcement and industry partners, conducted a successful disruption operation against the Sality botnet, which is now no longer under the operator’s control,” the cybersecurity company added.

    Law enforcement agencies worldwide have dismantled multiple other cybercrime operations since the start of the year as part of international joint actions.

    In March, American and European authorities, along with private partners, disrupted the SocksEscort cybercrime proxy network and took down Command and Control (C2) infrastructure used by the Aisuru, KimWolf, JackSkid, and Mossad botnets.

    More recently, Dutch authorities took a massive botnet of 17 million devices offline in May, and an FBI-led operation disrupted the QScan and QTRouter hacking platforms used by Chinese cyber-espionage groups.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    Botnet dismantled global infrastructure Joint Sality Takedown
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon

    US charges Russian for infecting 80,000 freelancers with malware

    23-Year-Old Sality P2P Botnet Disrupted

    WordPress backup plugin flaw exposes millions of sites to takeover attacks

    Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

    Chrome and Firefox Updates Patch Dozens of Vulnerabilities

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Lords call for AI ‘kill switch’ powers in UK

    September 3, 2026

    Sality botnet infrastructure dismantled in joint global takedown

    September 3, 2026

    How stablecoins are quietly becoming the Fed’s debt buyer of last resort

    September 3, 2026

    The universe has plenty of hydrogen. So why is star formation collapsing?

    September 3, 2026
    Latest Posts

    Australia news live: Reformers member tells hearing he used factional funds to pay for bucks night; Taylor refuses to answer multiple Icac-related questions | Australia news

    July 31, 2026

    Trump administration to end Medicare Part D subsidy program. Will costs increase?

    July 31, 2026

    FP Live: Daniel Yergin on Why Energy Prices Didn’t Soar Higher This Year

    July 31, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Lords call for AI ‘kill switch’ powers in UK

    September 3, 2026

    Sality botnet infrastructure dismantled in joint global takedown

    September 3, 2026

    How stablecoins are quietly becoming the Fed’s debt buyer of last resort

    September 3, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.