Sality botnet shut down by US and allies

Published September 2, 2026

US and European authorities took down Sality, a Windows botnet that has run since 2003. Investigators seized its infrastructure and hijacked its peer-to-peer network to cut infected machines off from the criminals who ran it.

Report priority
Medium
Targets
EggJagger+1 more

How it works

Sality spread itself for over two decades through infected USB drives, network shares, file sharing, compromised websites and email attachments, then infected machines used a peer-to-peer network instead of central servers to keep receiving commands and new malware.

What to do

Run a reputable antivirus or Microsoft Defender full scan on any Windows PC that shares files or USB drives, and watch for a notice from your antivirus vendor, ISP, or CrowdStrike/Shadowserver if your IP is flagged as previously infected.

Technical details

Affected software: EggJagger, Windows

Sality is a Windows file-infecting worm active since 2003, run by a threat actor tracked as Salty Spider (also Sality, Kukacka, KuKu, SalLoad, Kookoo, SaliCode), believed to operate out of Bashkortostan, Russia. Two incompatible peer-to-peer variants, v3 and v4, let infected hosts fetch commands without a central C2 server, controlling over 15,000 machines. Payloads included the EggJagger clipboard hijacker (over $150,000 in stolen crypto), credential stealers, spam and proxy tools, and DDoS capability used against forums in 2016, 2022, and 2023. On August 31, 2026, the DOJ, Bulgaria, Hungary, Romania, CrowdStrike, and Shadowserver sinkholed the P2P network and seized related domains.