[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fDDvCmWYpIadCp8TCw0Q6SKRrJM4fUUGN-6CQVpzcnQE":3},{"article":4,"iocs":52},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":29,"category":30,"article_tags":34},"d67eae05-205e-4402-bd70-b4ee93c117f2","Sality botnet infrastructure dismantled in joint global takedown","sality-botnet-infrastructure-dismantled-in-joint-global-takedown-db2015","International law enforcement agencies and private partners have seized Sality malware infrastructure in a joint action aiming to disrupt and take down the peer-to-peer (P2P) botnet. [...]","A coordinated international operation has successfully dismantled the Sality botnet, a peer-to-peer network active for over 20 years. Law enforcement agencies in the US, Bulgaria, Hungary, and Romania seized Sality-linked domains, while CrowdStrike sinkholed its control channels. The botnet, attributed to the SALTY SPIDER group operating from Russia, primarily pushed the EggJagger clipjacking malware and has historically been used for various malicious activities.","Global law enforcement and private partners dismantle the Sality botnet after two decades of operation.","Sality botnet infrastructure dismantled in joint global takedown By Sergiu Gatlan September 2, 2026 04:00 AM 0 International law enforcement agencies and private partners have seized Sality malware infrastructure in a joint action aiming to disrupt and take down the peer-to-peer (P2P) botnet. As part of this operation, supported by Europol and Eurojust, the U.S. Department of Justice (DOJ), FBI, and DCIS seized Sality-linked domains in the United States, while authorities in Bulgaria, Hungary, and Romania seized additional Sality-linked domains hosted in Europe. CrowdStrike's Counter Adversary Operations team, in collaboration with international law enforcement and private industry partners, also dismantled the botnet's control channels in a peer-to-peer sinkhole operation that isolated infected machines. The Sality botnet has been active for more than two decades and has infected over 15,000 devices with malware since at least 2003, when it first surfaced. CrowdStrike says Sality is controlled by a criminal group it tracks as SALTY SPIDER, which is likely operating out of the Republic of Bashkortostan in Russia. \"The victim computers infected with Sality were part of a peer-to-peer (P2P) botnet, which is a network of computers (each a 'bot) infected with the Sality malware and controlled by the Sality operator,\" the DOJ said. According to CrowdStrike, the two separate Sality botnet networks that were still active when the takedown took place this week were mainly used to push EggJagger malware payloads in clipjacking attacks. \"Throughout its history, Sality distributed a wide variety of distinct malware families spanning credential theft, spam distribution, proxy services, network exploitation, and distributed denial-of-service (DDoS) attacks,\" CrowdStrike said. \"For the past eight years, the primary payload has been EggJagger, a clipjacking tool that monitors the clipboard for cryptocurrency wallet addresses and silently replaces them with addresses controlled by the operator.\" Sality infected devices (CrowdStrike) ​The P2P botnet was disrupted by sinkholing Sality's list of known super peers, which form its communication backbone, to block file packs (direct payload transfers) and URL packs (payload download instructions) from propagating and purging infected machines' peer lists. \"After more than two decades of continuous operation, CrowdStrike, together with international law enforcement and industry partners, conducted a successful disruption operation against the Sality botnet, which is now no longer under the operator's control,\" the cybersecurity company added. Law enforcement agencies worldwide have dismantled multiple other cybercrime operations since the start of the year as part of international joint actions. In March, American and European authorities, along with private partners, disrupted the SocksEscort cybercrime proxy network and took down Command and Control (C2) infrastructure used by the Aisuru, KimWolf, JackSkid, and Mossad botnets. More recently, Dutch authorities took a massive botnet of 17 million devices offline in May, and an FBI-led operation disrupted the QScan and QTRouter hacking platforms used by Chinese cyber-espionage groups. Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report Related Articles: New Evooo1Bot Linux botnet turns routers into traffic relay nodesNew Dysphoria DDoS botnet spreads to 200k devices worldwideAnthropic warns infostealer malware is hijacking Claude sessions to drain usageToxicPanda Android malware uses VPN permissions to block Google PlayHackers infect Android car head units with proxy botnet malware","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fsality-botnet-infrastructure-dismantled-in-joint-global-takedown\u002F","https:\u002F\u002Fwww.bleepstatic.com\u002Fcontent\u002Fhl-images\u002F2026\u002F09\u002F02\u002FSality.jpg","2026-09-02T08:00:43+00:00","2026-09-02T10:00:10.146939+00:00",8,[18,21,24,27],{"name":19,"type":20},"SALTY SPIDER","threat_actor",{"name":22,"type":23},"CrowdStrike","vendor",{"name":25,"type":26},"Europol","product",{"name":28,"type":26},"Eurojust","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":29,"icon":31,"name":32,"slug":33},null,"Malware","malware",[35,40,42,47],{"category":36},{"id":37,"icon":31,"name":38,"slug":39},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":41},{"id":29,"icon":31,"name":32,"slug":33},{"category":43},{"id":44,"icon":31,"name":45,"slug":46},"c5eccf7c-abbc-4bd3-bbed-e6da5cba8e73","Incident Response","incident-response",{"category":48},{"id":49,"icon":31,"name":50,"slug":51},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]