{
  "id": 4948062,
  "title": "Russian cybercrime operation being dismantled after two decades, US officials and CrowdStrike say",
  "url": "https://urgent.news/2026/09/01/russian-cybercrime-operation-being-dismantled-after-two-decades-us-4948062",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-01T22:01:37.000Z",
  "source": {
    "name": "CNA - Business",
    "slug": "cna-business",
    "url": "https://www.channelnewsasia.com/business/russian-cybercrime-operation-being-dismantled-after-two-decades-us-officials-and-crowdstrike-say-6356051"
  },
  "original_language": "en",
  "account": "On September 1, the United States, in collaboration with European law enforcement and cybersecurity firm CrowdStrike, announced the dismantling of a Russian hacking operation known as Sality, which had operated for two decades. U.S. officials seized web domains utilized by hackers to distribute spam, execute distributed denial-of-service attacks, or steal cryptocurrency. CrowdStrike, meanwhile, cut off a network of compromised computers from the botnet's mastermind.\n\nThe FBI and U.S. Justice Department, in coordinated statements, confirmed the operation's execution in partnership with other organizations. Bill Essayli, First Assistant United States Attorney, emphasized the ongoing threat posed by cybercriminals, botnets, and malware to the nation's security and economy. Despite recent overshadowing by more disruptive ransom-seeking cybercriminals, Sality, first identified in 2003, remains one of the internet's longest-running cybercriminal enterprises.\n\nSality's peer-to-peer architecture, allowing it to receive commands through a diffuse network of compromised machines, made it particularly resilient to law enforcement action. However, CrowdStrike claimed to exploit this very strength by flooding the network with false information, causing the botnet's components to sever their connection with their creator. Reverse-engineering the botnet's structure and identifying weak points took significant effort, according to CrowdStrike researcher Tillmann Werner.\n\nDavid Watson, director of nonprofit security group The Shadowserver Foundation, acknowledged the botnet's age and resilience but highlighted its continued potential danger. Watson noted that Sality could still serve as an entry point for various organizations. The next step involves observing the botnet's creator, whose identity remains undisclosed, in their response to the takedown.",
  "summary": null,
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 3,
    "also_reported_by": [
      {
        "outlet": "Channel News Asia",
        "title": "Russian cybercrime operation being dismantled after two decades, US officials and CrowdStrike say",
        "url": "https://urgent.news/2026/09/01/russian-cybercrime-operation-being-dismantled-after-two-decades-us",
        "published": "2026-09-01T22:01:37.000Z"
      },
      {
        "outlet": "Investing.com",
        "title": "Russian cybercrime operation being dismantled after two decades, US officials and CrowdStrike say",
        "url": "https://urgent.news/2026/09/01/russian-cybercrime-operation-being-dismantled-after-two-decades-us-4950449",
        "published": "2026-09-01T22:06:27.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}