- The Mess: U.S. and European law enforcement, CrowdStrike and Shadowserver have disrupted Sality, a peer-to-peer botnet that survived for more than two decades.
- The Damage: More than 15,000 infected machines were part of an infrastructure used to distribute malware, steal cryptocurrency and deliver additional payloads.
- The Fix: Organizations should check for Sality infections immediately — the takedown stops new operator commands, but malware already running on infected machines does not magically disappear.
Some malware dies quickly.
Some malware gets patched.
Some malware survives long enough to become part of Internet history.
Sality survived for more than two decades.
Now someone finally turned its own architecture against it.
On August 31, an international operation involving U.S. law enforcement, European partners, CrowdStrike and the Shadowserver Foundation disrupted the Sality peer-to-peer botnet.
The interesting part?
They didn’t simply take down one command-and-control server.
Sality didn’t depend on one.
So defenders went inside the network.
A Botnet Designed to Survive Takedowns
Sality first appeared in 2003.
That alone makes it ancient by malware standards.
But age was part of the problem.
The malware evolved into a decentralized peer-to-peer botnet.
Instead of every infected computer connecting to one central command server, compromised machines could communicate through the network itself.
That architecture makes traditional takedowns considerably harder.
Take down one server?
The bots may simply find another peer.
Seize one domain?
The network may keep functioning.
Sality was designed to keep going.
And it did.
For more than twenty years.
More Than 15,000 Machines Were Still Connected
According to CrowdStrike, the criminal infrastructure was capable of distributing malicious payloads to more than 15,000 infected machines worldwide.
That’s an uncomfortable reminder.
Old malware doesn’t necessarily disappear.
Sometimes it simply stops making headlines.
Meanwhile, infected computers continue waiting for instructions.
Sality has been linked to malware delivery, cryptocurrency theft and other cybercriminal activity.
A compromised computer could become another node in a criminal infrastructure without its owner realizing what was happening.
CrowdStrike Turned the P2P Network Against Its Operator
This is where the operation becomes interesting.
Sality maintained lists of known peers.
Those peers formed the communication structure of the botnet.
CrowdStrike and its partners manipulated that structure.
Legitimate peers were progressively removed from infected machines.
Then purpose-built sinkhole entries were inserted into the network.
The result was devastating for the operator.
The infected machines gradually stopped finding legitimate nodes controlled by the criminal infrastructure.
Instead, they became isolated.
From the operator’s perspective:
the bots started disappearing.
And once isolated, they could no longer receive new instructions or download additional payloads.
The Botnet Got Sinkholed
A sinkhole operation sounds harmless.
It isn’t.
For the botnet operator, it means defenders take control of part of the network’s communication flow.
Instead of connecting to the criminal infrastructure, infected machines are redirected toward infrastructure controlled by defenders.
That serves two purposes.
First:
break the attacker’s command channel.
Second:
identify infected systems.
The Shadowserver Foundation is now working with ISPs and incident-response teams to help identify infections and notify affected victims.
Law Enforcement Took Down the Other Infrastructure
The P2P operation wasn’t the only move.
The U.S. Department of Justice, FBI and Defense Criminal Investigative Service also seized Sality-linked domains in the United States.
Authorities in:
- Bulgaria
- Hungary
- Romania
took action against additional Sality-linked domains hosted in Europe.
That matters because Sality could distribute URLs pointing to additional malicious payloads.
The peer-to-peer sinkhole disrupted communication.
The infrastructure takedown attacked the delivery mechanism.
The two operations were designed to hit the botnet from different directions.
This Wasn’t a Simple Domain Seizure
That’s the important distinction.
Cybercrime takedowns often follow a familiar pattern.
Find the server.
Seize the domain.
Shut down the hosting.
Done.
P2P botnets are much more annoying.
There may be no single server capable of killing the network.
The infected machines themselves become part of the infrastructure.
That was Sality’s strength.
It was also its weakness.
The network trusted its peers.
Defenders learned to speak the same language.
Then they poisoned the peer lists.
The Operator Lost the Command Channel
CrowdStrike says the disruption isolated infected machines from the operator’s control.
That means the bots could no longer receive:
- URL packs
- payload download instructions
- direct file transfers
- new tasking
The operator may still have created the malware.
They may still know how the protocol works.
But the existing botnet infrastructure is no longer communicating with them.
That’s a huge difference.
A malware author is dangerous.
A malware author controlling thousands of infected computers is considerably more dangerous.
The operation targeted the second problem.
The Malware Doesn’t Vanish
There is an important warning here.
A botnet takedown is not the same as disinfecting every victim.
The infected computers are still infected.
Existing malware already present on those systems may remain active.
The disruption prevents the operator from pushing new instructions through the disrupted infrastructure.
It doesn’t magically clean the machines.
Organizations still need to:
- identify infected endpoints
- investigate suspicious processes
- scan for indicators of compromise
- remove malware
- rotate potentially exposed credentials
- investigate previous malicious activity
The sinkhole protects the future communication channel.
It doesn’t erase the past.
Sality Was Still a Real Threat
There is a tendency to treat old malware as irrelevant.
Sality is proof that this can be a mistake.
According to reporting on the operation, the botnet remained a potential entry point into organizations and had been used for criminal activity including cryptocurrency theft and malicious payload delivery.
The fact that malware was first identified in 2003 doesn’t mean every infected machine was cleaned in 2004.
Internet archaeology can have consequences.
The Botnet Operator May Try to Come Back
One question remains.
What happens next?
The Sality operator has not been publicly identified.
The infrastructure has been disrupted.
The infected machines have been isolated from the command channel.
But operators can adapt.
They may attempt to:
- rebuild infrastructure
- create a replacement botnet
- distribute a new malware variant
- regain access to previously infected systems
That’s why a takedown isn’t necessarily the final chapter.
It’s a major blow.
Not a guarantee that the threat actor has disappeared forever.
Reuters reported that researchers are now watching to see whether the operator attempts to rebuild or regain control.
Old Malware Is Still Infrastructure
This story should make one thing obvious.
Cybercriminal infrastructure has a surprisingly long lifespan.
A botnet doesn’t need to remain fashionable.
It only needs to remain functional.
Thousands of forgotten infected computers can still provide:
- access
- bandwidth
- proxy infrastructure
- malware delivery
- credential theft opportunities
- DDoS capacity
The Internet is full of abandoned systems.
Attackers don’t need to compromise new computers every day if old compromises remain useful.
This Is What Active Defense Looks Like
Traditional cybersecurity often stops at detection.
Find malware.
Generate an alert.
Write a report.
Hope someone cleans it.
The Sality operation went further.
The defenders actively disrupted the attacker’s infrastructure.
They manipulated the network.
They seized domains.
They redirected communications.
They isolated infected machines.
That’s considerably more aggressive than simply publishing indicators of compromise.
And it’s probably where large-scale botnet defense needs to go.
Check for Sality Anyway
Organizations should not assume the takedown means they are automatically safe.
CrowdStrike published detection material and guidance for identifying active Sality infections.
The company specifically warns that the disruption stops new payload delivery but does not remove malware already present on compromised systems.
If Sality is detected:
isolate the endpoint.
Then investigate what else happened.
A botnet infection can be the beginning of a much larger compromise.
Bugstoday Opinion
There is something deeply satisfying about this takedown.
Sality spent more than twenty years surviving because it didn’t trust a single command server.
Its decentralized architecture made it difficult to kill.
So defenders didn’t try to attack one central brain.
They attacked the relationships between the machines.
Then they made the bots slowly cut themselves off from their operator.
Bugstoday verdict: this wasn’t just another domain seizure. CrowdStrike and law enforcement effectively hacked the botnet’s own communication model and turned its resilience into its weakness. The malware is still on infected machines, and the operator may try to rebuild, but one of the Internet’s longest-running criminal infrastructures has just lost the thing that made it valuable: control.
Today’s Bugs. Tomorrow’s Breaches.
Sources
- U.S. Department of Justice — Sality Malware Disrupted in International Cyber Takedown
- CrowdStrike — Inside the Sality Botnet Disruption Operation
- FBI — Cybercrime and Botnet Disruption
- Shadowserver Foundation
- Europol — Cybercrime Cooperation




