{
  "id": 4982401,
  "title": "Russian cybercrime operation being dismantled after two decades: U.S. and CrowdStrike",
  "url": "https://urgent.news/2026/09/02/russian-cybercrime-operation-being-dismantled-after-two-decades-u-s",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-02T01:17:00.000Z",
  "source": {
    "name": "Japan Times",
    "slug": "japan-times",
    "url": "https://www.japantimes.co.jp/news/2026/09/02/world/russian-cybercrime-us-crowdstrike/"
  },
  "original_language": "en",
  "account": "In a significant operation, U.S. law enforcement and cybersecurity firm CrowdStrike have dismantled a two-decade-old Russian hacking group known as \"Sality.\" The joint effort resulted in the seizure of web domains utilized by the hackers to carry out spam campaigns, distributed denial-of-service attacks, and cryptocurrency thefts. CrowdStrike also severed a network of compromised computers that were under the control of the botnet's mastermind.\n\nThe dismantling of Sality took place on Monday during a live event at CrowdStrike's Day Zero threat intelligence summit in Las Vegas. The FBI and U.S. Justice Department confirmed the operation was carried out in coordination with European law enforcement and other organizations, emphasizing the ongoing threat posed by cybercriminals, botnets, and malware to national security and the economy.\n\nAlthough Sality has been overshadowed by more aggressive ransomware groups in recent years, it remains one of the internet's longest-running cybercriminal enterprises. First spotted in 2003, the operation was based in Russia, though the Russian Embassy in Washington did not provide further details.\n\nSality's peer-to-peer architecture made it particularly resilient to law enforcement efforts, as it could receive commands through a diffuse network of compromised machines. However, CrowdStrike managed to exploit this very strength by flooding the network with false information, causing the botnet components to disconnect from their creator.\n\nCrowdStrike researcher Tillmann Werner highlighted the complexity of the operation, stating that it was the most challenging botnet takeover they had ever undertaken. The painstaking process involved reverse-engineering the botnet's structure, identifying weak points, and building the necessary infrastructure to dismantle it.\n\nDavid Watson, director of the nonprofit security group The Shadowserver Foundation, which also participated in the takedown, noted that while Sality is \"quite old-school,\" it still poses a significant threat. Watson emphasized the need to observe the actions of the botnet's creator, who has yet to be publicly identified, to determine if they will attempt to regain control or recreate the botnet.",
  "summary": "Though it has been overshadowed by more disruptive cybercriminals, the Russian hacking operation remains one of the internet's longest-running cybercriminal enterprises.",
  "key_points": [
    "U.S. and CrowdStrike dismantle Russian cybercrime group Sality after 20 years",
    "Joint operation seized domains and compromised computers used for spam, DDoS, and crypto thefts",
    "Sality, first seen in 2003, was resilient due to peer-to-peer architecture and botnet control"
  ],
  "editors_take": "The dismantling of Sality marks a significant blow to long-running cybercrime operations, demonstrating that even resilient peer-to-peer botnets can be taken down with concerted law enforcement and cybersecurity efforts.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}