US and allies dismantle 23 year old Sality botnet
US and European authorities disrupted Sality, a malware network that has operated since around 2003. The operation blocked its controller from sending new instructions or malware to infected computers. CrowdStrike says Sality had distributed malware to more than 33,000 infected computers worldwide. Malware already installed on those computers remains active and can still replace copied cryptocurrency payment addresses.
- Started
- Aug 31, 2026
- Latest activity
- Sep 4, 2026
- Attributed to
- RussiaSuspected
- Where
- United States, Bulgaria, Hungary, Romania
- Sectors
- Consumers
- Scale
- more than 33,000 infected computers worldwide
Current status
No credible reporting or official statement dated after 2026-09-08 was found as of 2026-09-11.
Contained: The attack has been stopped or blocked. Recovery and investigation are still running.
Who is behind it
CrowdStrike and Europol described Sality as a Russia-based or Russia-linked criminal operation in their September 2026 statements, but no specific person or group has been named and no government has issued a formal attribution.
Impact
The operator can no longer send new instructions or malware through the Sality network. However, the EggJagger malware already installed on infected computers can still replace copied Bitcoin and Ethereum payment addresses. Those computers remain unsafe until the malware is removed.
What to do
Run an up-to-date antivirus scan on any Windows computer that may be infected. Before sending cryptocurrency, compare the pasted payment address with the intended address. Organizations should investigate any Sality warning from their internet provider, Shadowserver, or a national cybersecurity agency and remove the malware from affected computers.
Timeline
-
Sep 8, 2026
CryptoSlate reported that Sality's command channel remains blocked, but the EggJagger malware already installed on infected computers can still replace copied cryptocurrency payment addresses. It also reported CrowdStrike's count of more than 33,000 infected computers worldwide.
Containedcryptoslate.com -
Sep 4, 2026
Europol and CrowdStrike described Sality as a Russia-based botnet and detailed how its peer-to-peer design let infections regenerate without phishing or exploit kits, making it unusually hard to dismantle even after the takedown.
Containedtechcentral.ie -
Sep 3, 2026
Shadowserver Foundation began working with internet providers and national cybersecurity agencies to identify and contact owners of machines still infected with Sality, using data from CrowdStrike's sinkhole.
Containedyahoo.com -
Sep 2, 2026
The Justice Department publicly announced the disruption, saying more than 15,000 infected machines had been cut off from the botnet's peer network and payload servers.
Containedsecurityweek.com -
Aug 31, 2026
US, Bulgarian, Hungarian, and Romanian authorities carried out a coordinated takedown of Sality botnet infrastructure with CrowdStrike and the Shadowserver Foundation.
Containedthehackernews.com
Sources
- 23-Year-Old Sality P2P Botnet Disrupted SecurityWeek Sep 2, 2026
- Authorities Turn Sality's P2P Network Against Itself TheHackerNews Aug 20, 2026
- Sality botnet infrastructure dismantled in joint global takedown Bleeping Computer Sep 2, 2026
- Sality Botnet Dismantled After Eight Years of Stealing Bitcoin and Ethereum Decrypt Sep 2, 2026
- International effort shuts down long-running Sality botnet TechCentral.ie Sep 4, 2026
- Government, industry partner to shut down long-running Sality botnet Yahoo News Sep 3, 2026
- US Just Took Down a 20-Year-Old Russian-Linked Cybercrime Operation Yahoo News Sep 4, 2026
- Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes The Register Sep 2, 2026
- Russian Cybercrime Operation Being Dismantled After Two Decades, US Officials and CrowdStrike Say U.S. News (Reuters) Sep 1, 2026 unverified
- Active crypto address "copy and paste attack" threatens users even after major malware cleanup cut off hacker controls CryptoSlate Sep 8, 2026
Related reports
- FBI shuts down 23-year-old Sality botnet Sep 2, 2026