> Back to All Posts

Sality Botnet Seized After 23 Years of Crypto Theft

Sality botnet

A piece of malware that first appeared in 2003 has finally run out of road. Law enforcement agencies across several countries seized the infrastructure behind the Sality botnet this week, and private security firms handled the technical side of the operation. The malware survived 23 years of antivirus updates, operating system rewrites, and earlier cleanup attempts. Now its command network answers to investigators instead of criminals.

The Sality botnet never worked like an ordinary criminal network, and that difference kept it alive for so long. Instead of leaning on a few central servers, it linked infected computers directly to one another. Take one node offline and the rest carried on without it. So investigators had to attack the structure itself rather than a single point of failure.

What the Sality botnet did for two decades

Sality first surfaced in 2003, and it never specialized in one type of crime. Over the years it delivered credential stealers, pushed spam, and rented infected machines out as proxies. It also spread network exploitation tools and launched denial-of-service attacks, because the operators swapped payloads whenever a new revenue stream looked more profitable. That flexibility explains the long run.

More than 15,000 devices carried the infection when the takedown began, which is a modest figure next to modern botnets counting victims in the millions. But raw size was never the point here. Each compromised machine had sat unnoticed for years, often on outdated Windows systems with no monitoring in place. Quiet persistence beat scale.

Inside the Sality botnet takedown

The Sality botnet takedown came together across two continents. Investigators from the U.S. Department of Justice, the FBI, and the Defense Criminal Investigative Service seized Sality-linked domains inside the United States. At the same time, police in Bulgaria, Hungary, and Romania seized further domains sitting on European servers. CrowdStrike’s Counter Adversary Operations team handled the technical work alongside law enforcement and industry partners.

Their approach targeted the super peers, the nodes that form the communication backbone of the network. Researchers sinkholed those peers, so infected machines began talking to systems under investigator control. Two kinds of traffic then stopped moving, because file packs carry payloads directly and URL packs tell bots where to download fresh code. The team also purged the peer lists on infected devices, since bots that cannot find each other cannot rebuild.

Why peer-to-peer botnets resist shutdown

Most botnets rely on command and control servers, so seizing those servers takes the network dark. Peer-to-peer designs remove that weakness by turning every infected machine into part of the control layer. A takedown therefore has to reach most active nodes at once, and it has to hold. Partial disruption only gives operators time to rebuild.

Clipjacking and the EggJagger payload

For the past eight years, one payload has dominated the Sality botnet. EggJagger is a clipjacking tool, and it watches the clipboard for cryptocurrency wallet addresses. When it finds one, it quietly swaps in an address the operator controls. The victim pastes what looks correct, confirms the transaction, and sends the money straight to a criminal.

That attack works because almost nobody reads a 42-character wallet address twice. Nobody can reverse a crypto transfer either, so the theft becomes final once the network confirms it. Two separate Sality networks were still running EggJagger campaigns when the operation began, and both went dark. Between them, they made up the last active remnants of a two-decade operation.

The group behind the Sality botnet

CrowdStrike tracks the crew behind the malware as SALTY SPIDER and places it in the Republic of Bashkortostan in Russia. That group kept the same core infrastructure running for more than twenty years. Criminal brands appear and vanish within months, so such longevity stands out. Researchers now describe the Sality botnet as out of its operator’s hands entirely.

A busy year for botnet disruptions

The Sality botnet operation joins a steady run of coordinated actions through 2026. In March, American and European authorities disrupted the SocksEscort proxy network. They also seized the command infrastructure serving the Aisuru, KimWolf, JackSkid, and Mossad botnets. Dutch investigators followed in May and pulled a botnet of 17 million devices offline.

An FBI-led operation later hit the QScan and QTRouter platforms that Chinese espionage groups relied on. These operations share a pattern worth noticing. Security vendors bring the telemetry and the technical capability, while police bring the legal authority to seize domains and servers. Neither side gets far alone.

What users should do now

A sinkhole cuts the connection, but it does not clean the machine. Anyone running an older Windows system should scan it with current security software and switch automatic updates back on. Sality spread through removable drives, network shares, and infected executables. So one neglected computer on a home network can still create problems for everything around it.

Crypto users need an extra habit on top of that. Check the first and last characters of a wallet address after every paste, and confirm larger transfers on a second device before you approve them. A VPN will not remove malware, though it does hide your traffic from anyone watching the local network. Layered habits beat any single tool.

Final Thoughts

Twenty-three years is an extraordinary run for any piece of software, and criminal tools rarely last a fraction of that. The Sality botnet survived because its design offered no obvious throat to cut. It also survived because thousands of neglected computers kept feeding it. Dismantling it took patience, cross-border cooperation, and a plan targeting the architecture rather than a server rack.

This takedown also closes a quiet revenue stream that ran on clipboard theft. Clipjacking victims rarely notice anything wrong, and they almost never recover the money. So fewer active nodes means fewer stolen transfers and fewer people staring at an empty wallet. For a threat this old, that is a fitting end.

Janet Andersen

Janet is an experienced content creator with a strong focus on cybersecurity and online privacy. With extensive experience in the field, she’s passionate about crafting in-depth reviews and guides that help readers make informed decisions about digital security tools. When she’s not managing the site, she loves staying on top of the latest trends in the digital world.