{
  "id": 5007054,
  "title": "Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes",
  "url": "https://urgent.news/2026/09/01/cops-crowdstrike-disrupt-sality-botnet-by-poisoning-the-network-and-5007054",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-01T23:54:07.000Z",
  "source": {
    "name": "The Register",
    "slug": "the-register",
    "url": "https://www.theregister.com/cyber-crime/2026/09/02/cops-crowdstrike-disrupt-sality-botnet-by-poisoning-the-network-and-diverting-into-sinkholes/5293795"
  },
  "original_language": "en",
  "account": "On Monday, international law enforcement agencies, in collaboration with CrowdStrike and Shadowserver Foundation, successfully dismantled the Sality botnet, a 23-year-old peer-to-peer network that infected over 15,000 computers worldwide. The botnet, active since 2003, was responsible for a wide range of malicious activities, including stealing credentials, spreading spam, providing proxy services, exploiting networks, and executing distributed denial-of-service (DDoS) attacks. For the past eight years, Sality primarily delivered EggJagger, a tool that monitored user clipboards for cryptocurrency wallet addresses, then covertly replaced them with addresses controlled by the attackers. When a victim copied a Bitcoin or Ethereum address for a payment, the malware rerouted the funds to the criminals' accounts, with CrowdStrike estimating that the botnet's operators had stolen at least $150,000 in cryptocurrency using EggJagger alone.\n\nCrowdStrike's Counter Adversary Operations team, working alongside international law enforcement and industry partners, executed a peer-to-peer sinkhole operation to disrupt Sality. This operation isolated infected machines, severing the criminals' ability to communicate with devices on their network. As a result, the bots could no longer receive instructions for payload downloads or transfers, effectively dismantling the botnet. The technical writeup from CrowdStrike's Counter Adversary Operations team explained that the operation targeted the core data structure of each bot's network awareness: its peer list. Every 40 minutes, the bots checked their peers to see if they were still online. Peers that failed to respond were removed from the network. The counterattack took advantage of this process by removing legitimate super peers from each bot's peer list, continually isolating more infected machines, and inserting purposely-built sinkhole entries into the peer lists. This approach provided police and cyber operatives with visibility into the operation's progress and facilitated the notification of victims. Furthermore, the US Justice Department, FBI, and Department of Defense Office of Inspector General's Defense Criminal Investigative Service seized Sality-linked domains in the United States, while international law enforcement in Bulgaria, Hungary, and Romania took action against additional Sality-linked domains hosted in Europe. The Shadowserver Foundation is currently working with internet service providers and Computer Security Incident Response Teams (CSIRTs) to identify infections and assist in victim notification and remediation.",
  "summary": "23-year-old botnet down",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}