Stock Markets September 2, 2026 06:07 PM

Two-Decade-Old 'Sality' Botnet Targeted in Coordinated Takedown by U.S. Authorities and CrowdStrike

Law enforcement seizes malicious domains while cybersecurity firm isolates compromised machines in live demonstration

By Caleb Monroe
Share
Twitter Reddit Facebook LinkedIn
CRWD

U.S. officials and cybersecurity firm CrowdStrike announced a coordinated effort to dismantle Sality, a long-running Russian-based botnet first identified in 2003. Authorities said they seized web domains used by the operation to control infected machines, while CrowdStrike reported it had cut compromised hosts off from the botnet's controller by feeding false data into the peer-to-peer network. The action was revealed during CrowdStrike's Day Zero summit in Las Vegas and involved collaboration with European partners and nonprofit security groups.

Two-Decade-Old 'Sality' Botnet Targeted in Coordinated Takedown by U.S. Authorities and CrowdStrike
CRWD
Summarize with
ChatGPT Perplexity Claude Grok Gemini

Key Points

  • Sality is a Russia-based botnet first detected in 2003 that U.S. authorities and CrowdStrike have targeted for dismantling.
  • Authorities seized web domains used by the operation while CrowdStrike isolated compromised machines by injecting false data into the botnet.
  • The disruption affects cybersecurity, internet infrastructure, and organizations vulnerable to spam, DDoS attacks, and cryptocurrency theft.

U.S. law enforcement agencies and cybersecurity company CrowdStrike said on Tuesday that they have moved to dismantle Sality, a Russian-based hacking operation that has been active for roughly two decades. Officials reported that they seized multiple web domains used by the malware authors to commandeer infected computers to send spam, mount distributed denial-of-service attacks, or steal cryptocurrency.

CrowdStrike said it had also taken steps to sever a network of compromised machines from the botnet's operator. The firm began its technical intervention on Monday as part of a live demonstration at its Day Zero threat intelligence summit in Las Vegas, when researchers deployed measures designed to disrupt the botnet's command infrastructure.

The FBI and the U.S. Department of Justice issued statements on Tuesday saying the operation was conducted in coordination with law enforcement in Europe and with other organizations. First Assistant United States Attorney Bill Essayli emphasized the broader implications in a statement announcing the action: "Cybercriminals, botnets, and malware are a clear and present danger to our nation’s security and economy."

Sality, which was first observed in 2003, has remained among the internet's longest-running cybercriminal operations, even as newer ransomware-focused groups have drawn more attention in recent years. The Justice Department confirmed the botnet was based out of Russia but provided no additional specifics. The Russian Embassy in Washington did not immediately respond to requests for comment.

Part of Sality's resilience stems from its peer-to-peer architecture. That design permitted the botnet to receive instructions through a widely distributed mesh of infected machines, making it notably resistant to traditional law enforcement disruption techniques.

In a blog post published Tuesday, CrowdStrike described how it leveraged those same structural features to neutralize the net. Researchers said they seeded the network with deceptive information that induced elements of the botnet to isolate themselves from their controller.

Tillmann Werner, a researcher at CrowdStrike, described the effort as painstaking and technically demanding. "This was the most complex botnet takeover we have ever done," he said, adding: "This was built to be resilient. It was built to survive takedown or takeover. I think that’s the reason it’s been around for so long."

Nonprofit security group The Shadowserver Foundation, represented by director David Watson, also participated in the takedown. Watson characterized Sality as "quite old-school" but warned it still posed risks to organizations. "It’s still a vector into a lot of organizations," he said.

Watson noted the next phase will involve monitoring to determine whether the unknown author of Sality attempts to regain control of the existing network or to recreate the botnet from scratch. "What does he do?" Watson asked. "Does he fight back?"

The company named in the operation, CrowdStrike Holdings Inc, is commonly identified by the ticker CRWD. The coordinated action combined legal measures to seize control points with technical measures to disrupt the peer-to-peer communications that sustained the botnet.


Summary

A coordinated operation by U.S. authorities, European partners, CrowdStrike, and nonprofit security groups targeted Sality, a peer-to-peer botnet first seen in 2003 and based out of Russia according to the Justice Department. Authorities say they seized web domains used by the malware operators, while CrowdStrike reported it tricked parts of the botnet into severing links with its controller during a live demonstration at its Las Vegas conference. Researchers and security partners will now monitor whether the unidentified creator attempts to retake or rebuild the botnet.

Key points

  • Sality is a long-running Russian-based botnet first identified in 2003 and has been targeted for dismantling by U.S. law enforcement and CrowdStrike.
  • U.S. officials said web domains used by the operation were seized; CrowdStrike said it cut compromised machines off from the botnet's controller by seeding false information into the network.
  • Sectors affected include cybersecurity providers, internet infrastructure and hosting services, and organizations vulnerable to spam, DDoS attacks, or cryptocurrency theft.

Risks and uncertainties

  • It is unclear whether the botnet's creator, who has not been publicly identified, will attempt to regain control or reconstitute the network - a risk for any organizations still exposed to remnants of the botnet.
  • Because Sality relied on a resilient peer-to-peer design, remnants or variants could continue to pose a threat, affecting internet infrastructure and businesses that rely on robust network security.

Risks

  • Uncertainty over whether the unidentified botnet author will attempt to regain control or rebuild the network - risk to organizations still exposed.
  • The botnet’s peer-to-peer resilience means remnants or variants could continue to threaten internet infrastructure and affected businesses.

More from Stock Markets

U.S. Antitrust Probe into Beef Prices Widens to Include Eight Major Retailers Sep 2, 2026 Olympus-Backed Accelevation Moves Toward U.S. IPO as AI Infrastructure Demand Rises Sep 2, 2026 JPMorgan Pulls Back Financing to Jane Street as Bond Market Competition Intensifies Sep 2, 2026 Colombian Equities Close Higher as Industrials, Services and Agriculture Propel Gains Sep 2, 2026 Moscow stocks slip as miners and manufacturers lead declines; MOEX down 0.34% Sep 2, 2026