Skip to content
See the World Through ScienceA project of ALLATRA

A Botnet Running Since 2003 Has Lost Contact With Its Operator

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

The Europol headquarters in The Hague: a modern brick-and-glass office block with the Europol name mounted on its facade and a signpost at the entrance.
Europol's headquarters in The Hague. Europol was among the bodies that supported the Aug. 31 disruption operation; this photograph is illustrative and does not show the operation."Europol building, The Hague, the Netherlands - 002" by OSeveno, via Wikimedia Commons, licensed under CC BY-SA 3.0 · CC-BY-SA-3.0

CrowdStrike's Counter Adversary Operations team, working with U.S. and European law enforcement, disrupted the Sality botnet on Aug. 31, 2026, cutting off the machines it had infected from the operator who had run it since 2003. The company described the operation in an incident report published Sept. 1.

CrowdStrike says the botnet reached more than 15,000 infected machines worldwide. The action was a peer-to-peer sinkholing operation that, in the company's description, isolates those machines and renders the operator's command channel inert. Partners in the operation, CrowdStrike says, include the U.S. Department of Justice, the FBI, the Defense Criminal Investigative Service and the Shadowserver Foundation, with support from Europol, Eurojust and law enforcement agencies in Bulgaria, Hungary and Romania. Investigators also took down the web addresses that were hosting Sality's payloads at the time.

Sality is a file-infecting malware first observed in 2003, according to CrowdStrike. It spread by attaching itself to programs on infected computers and traveling over network shares, removable drives and file sharing, so infections regenerated without any active effort from the operator. The malware had no central control server: infected machines passed instructions directly to one another. Two separate networks, which CrowdStrike calls version 3 and version 4, shared a codebase and one operator and were both running until this week, the company says.

The botnet's only technical job was to install other malware. For the past eight years, the main payload has been a clipboard-watching tool that swaps a copied cryptocurrency wallet address for one the operator controls, CrowdStrike says, and the company estimates that at least 12.1 million rubles, about $150,000, was stolen that way. That figure covers only that one payload.

CrowdStrike wrote that the operation "demonstrates that P2P architecture, long considered a shield against disruption, is not invincible." Infected computers now contact sinkholes the company operates, and CrowdStrike says the malware already installed on those machines remains active and still has to be removed.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

A Botnet Running Since 2003 Has Lost Contact With Its Operator

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.