A Botnet Running Since 2003 Has Lost Contact With Its Operator

CrowdStrike's Counter Adversary Operations team, working with U.S. and European law enforcement, disrupted the Sality botnet on Aug. 31, 2026, cutting off the machines it had infected from the operator who had run it since 2003. The company described the operation in an incident report published Sept. 1.
CrowdStrike says the botnet reached more than 15,000 infected machines worldwide. The action was a peer-to-peer sinkholing operation that, in the company's description, isolates those machines and renders the operator's command channel inert. Partners in the operation, CrowdStrike says, include the U.S. Department of Justice, the FBI, the Defense Criminal Investigative Service and the Shadowserver Foundation, with support from Europol, Eurojust and law enforcement agencies in Bulgaria, Hungary and Romania. Investigators also took down the web addresses that were hosting Sality's payloads at the time.
Sality is a file-infecting malware first observed in 2003, according to CrowdStrike. It spread by attaching itself to programs on infected computers and traveling over network shares, removable drives and file sharing, so infections regenerated without any active effort from the operator. The malware had no central control server: infected machines passed instructions directly to one another. Two separate networks, which CrowdStrike calls version 3 and version 4, shared a codebase and one operator and were both running until this week, the company says.
The botnet's only technical job was to install other malware. For the past eight years, the main payload has been a clipboard-watching tool that swaps a copied cryptocurrency wallet address for one the operator controls, CrowdStrike says, and the company estimates that at least 12.1 million rubles, about $150,000, was stolen that way. That figure covers only that one payload.
CrowdStrike wrote that the operation "demonstrates that P2P architecture, long considered a shield against disruption, is not invincible." Infected computers now contact sinkholes the company operates, and CrowdStrike says the malware already installed on those machines remains active and still has to be removed.
