FBI shuts down 23-year-old Sality botnet

Published September 2, 2026

Sality is a 23-year-old virus that infects Windows program files and links infected machines into a peer-to-peer botnet. Law enforcement and CrowdStrike just shut it down, cutting off its ability to steal cryptocurrency through a clipboard-hijacking tool called EggJagger.

Report priority
Medium
Targets
EggJagger

How it works

Sality bots trusted any peer on their network without checking who it really was, so CrowdStrike rewrote the peer lists infected machines share to cut them off from real controllers and redirect them to sinkhole servers, while police in the US, Bulgaria, Hungary, and Romania took down the web addresses hosting Sality's malicious files.

What to do

Run a full antivirus or malware scan on any Windows machine you suspect is infected, and watch for a notification from your internet provider if Shadowserver's outreach identifies your network.

Technical details

Sality (tracked by CrowdStrike as SALTY SPIDER) is a file-infecting virus first seen in 2003 that avoids a central command server by coordinating over a P2P network of 'super peers,' infected hosts that gain or lose reputation based on uptime. CrowdStrike abused this trust-based reputation system to purge real super peers from bot peer lists and inject sinkhole nodes it controls, isolating infected machines from their operator. Simultaneously, law enforcement in the US, Bulgaria, Hungary, and Romania seized the URLs hosting new Sality payloads. All Sality bots now beacon to CrowdStrike sinkholes instead of criminal infrastructure, and the Shadowserver Foundation is coordinating with ISPs and CSIRTs to identify and clean up victims.