Sality botnet shut down by US and allies
US and European authorities took down Sality, a Windows botnet that has run since 2003. Investigators seized its infrastructure and hijacked its peer-to-peer network to cut infected machines off from the criminals who ran it.
- Report priority
- Medium
- Targets
- EggJagger+1 more
How it works
Sality spread itself for over two decades through infected USB drives, network shares, file sharing, compromised websites and email attachments, then infected machines used a peer-to-peer network instead of central servers to keep receiving commands and new malware.
What to do
Run a reputable antivirus or Microsoft Defender full scan on any Windows PC that shares files or USB drives, and watch for a notice from your antivirus vendor, ISP, or CrowdStrike/Shadowserver if your IP is flagged as previously infected.
Technical details
Affected software: EggJagger, Windows
Sality is a Windows file-infecting worm active since 2003, run by a threat actor tracked as Salty Spider (also Sality, Kukacka, KuKu, SalLoad, Kookoo, SaliCode), believed to operate out of Bashkortostan, Russia. Two incompatible peer-to-peer variants, v3 and v4, let infected hosts fetch commands without a central C2 server, controlling over 15,000 machines. Payloads included the EggJagger clipboard hijacker (over $150,000 in stolen crypto), credential stealers, spam and proxy tools, and DDoS capability used against forums in 2016, 2022, and 2023. On August 31, 2026, the DOJ, Bulgaria, Hungary, Romania, CrowdStrike, and Shadowserver sinkholed the P2P network and seized related domains.