Contained Medium impact Fraud Checked 9h ago

US and allies dismantle 23 year old Sality botnet

US and European authorities disrupted Sality, a malware network that has operated since around 2003. The operation blocked its controller from sending new instructions or malware to infected computers. CrowdStrike says Sality had distributed malware to more than 33,000 infected computers worldwide. Malware already installed on those computers remains active and can still replace copied cryptocurrency payment addresses.

Started
Aug 31, 2026
Latest activity
Sep 4, 2026
Attributed to
RussiaSuspected
Where
United States, Bulgaria, Hungary, Romania
Sectors
Consumers
Scale
more than 33,000 infected computers worldwide

Current status

No credible reporting or official statement dated after 2026-09-08 was found as of 2026-09-11.

Contained: The attack has been stopped or blocked. Recovery and investigation are still running.

Who is behind it

CrowdStrike and Europol described Sality as a Russia-based or Russia-linked criminal operation in their September 2026 statements, but no specific person or group has been named and no government has issued a formal attribution.

Impact

The operator can no longer send new instructions or malware through the Sality network. However, the EggJagger malware already installed on infected computers can still replace copied Bitcoin and Ethereum payment addresses. Those computers remain unsafe until the malware is removed.

What to do

Run an up-to-date antivirus scan on any Windows computer that may be infected. Before sending cryptocurrency, compare the pasted payment address with the intended address. Organizations should investigate any Sality warning from their internet provider, Shadowserver, or a national cybersecurity agency and remove the malware from affected computers.

Timeline

  1. Sep 8, 2026

    CryptoSlate reported that Sality's command channel remains blocked, but the EggJagger malware already installed on infected computers can still replace copied cryptocurrency payment addresses. It also reported CrowdStrike's count of more than 33,000 infected computers worldwide.

    Containedcryptoslate.com
  2. Sep 4, 2026

    Europol and CrowdStrike described Sality as a Russia-based botnet and detailed how its peer-to-peer design let infections regenerate without phishing or exploit kits, making it unusually hard to dismantle even after the takedown.

    Containedtechcentral.ie
  3. Sep 3, 2026

    Shadowserver Foundation began working with internet providers and national cybersecurity agencies to identify and contact owners of machines still infected with Sality, using data from CrowdStrike's sinkhole.

    Containedyahoo.com
  4. Sep 2, 2026

    The Justice Department publicly announced the disruption, saying more than 15,000 infected machines had been cut off from the botnet's peer network and payload servers.

    Containedsecurityweek.com
  5. Aug 31, 2026

    US, Bulgarian, Hungarian, and Romanian authorities carried out a coordinated takedown of Sality botnet infrastructure with CrowdStrike and the Shadowserver Foundation.

    Containedthehackernews.com

Sources

Related reports