- The Mess: Sality survived for roughly 23 years by doing something attackers love: removing the central server from the equation. An international operation involving the DOJ, FBI, Europol, CrowdStrike and Shadowserver has now disrupted the peer-to-peer botnet and severed its remaining infected machines from the criminal infrastructure.
Sality first appeared around 2003.
Back then it was a file-infecting virus that spread through executable files, network shares, removable media and other distribution paths.
It eventually evolved into a resilient peer-to-peer botnet.
That architecture became its biggest defensive advantage.
There was no single command server to seize.
Infected machines communicated with other infected machines, creating a distributed control layer that could survive individual infrastructure takedowns.
According to Europol, more than 11 million unique IP addresses have been associated with Sality infrastructure over its lifetime. At its peak, the botnet provided access to as many as one million infected machines.
The operation carried out on August 31 attacked the architecture itself.
CrowdStrike and the Shadowserver Foundation performed a coordinated peer-to-peer sinkholing operation, redirecting infected systems away from the criminal control network and isolating them from the operator.
Law enforcement agencies in the United States, Bulgaria, Hungary and Romania also seized Sality-linked domains.
The result: the operator lost the ability to communicate with the remaining botnet population.
- The Damage: Sality was not just an old virus — its infrastructure delivered malware, credential theft, spam, proxy services, DDoS capabilities and cryptocurrency theft to compromised systems around the world.
For the last several years, one of its major payloads was EggJagger.
The malware monitored cryptocurrency addresses copied to the clipboard and replaced legitimate wallet addresses with attacker-controlled ones.
A victim could copy a Bitcoin or Ethereum address, paste it into a transaction and unknowingly send the money to the criminals.
CrowdStrike estimates that EggJagger alone generated at least $150,000 in stolen cryptocurrency.
That was only one revenue stream.
Sality had previously been used to distribute credential stealers, spam campaigns, proxy software and DDoS payloads.
The interesting part is what happened after the takedown.
Authorities did not simply unplug a server.
They had to understand how the P2P network selected and communicated with its peers, then manipulate that system so infected machines would communicate with infrastructure controlled by defenders.
That is why this operation matters beyond Sality.
A centralized botnet can be decapitated.
A decentralized botnet has to be rewired.
CrowdStrike described the operation as an effort to isolate infected machines and render the criminal command channel inert. Shadowserver is now working with internet service providers and incident-response teams to identify remaining infections and help notify victims.
- The Fix: Organizations should still scan for Sality infections, remove infected executables and investigate suspicious network traffic — the takedown disrupts the criminal infrastructure but does not automatically clean infected computers.
The fact that Sality has been sinkholed does not mean every infected machine is suddenly healthy.
The malware is still sitting on endpoints.
A compromised system can still contain malicious files, stolen credentials or additional payloads even if its connection to the original operator has been broken.
Defenders should therefore treat Sality detection as an incident-response problem rather than assuming the takedown solved the endpoint infection.
For organizations using older Windows systems, removable media and shared executable files deserve particular attention because of Sality’s long history as a file infector.
Bugstoday Opinion
Twenty-three years.
Most malware families disappear because their infrastructure gets seized, their operators get arrested or newer malware replaces them.
Sality kept going.
Its secret wasn’t sophisticated AI or some magical zero-day.
It was architecture.
No central server.
No single switch to turn off.
No obvious head to cut off.
The attackers built a network that behaved like a hydra. Law enforcement responded by poisoning the peer relationships themselves.
That’s the interesting lesson here.
Decentralization helps criminals too.
And Sality proves that malware doesn’t need to be new to remain dangerous. An infection chain built in 2003 was still generating criminal revenue decades later.
The takedown is a win.
But the infected machines are still somebody’s problem.
Today’s Bugs. Tomorrow’s Breaches.
Sources
U.S. Department of Justice — Sality Malware Disruption International Cyber Takedown
Europol — Global Public-Private Operation Disrupts Sality Botnet
CrowdStrike — Inside the Sality Botnet Disruption Operation
Shadowserver Foundation — Sality Botnet Disruption and Victim Notification
FBI — Sality Disruption Operation




