- Authorities in the United States, Bulgaria, Hungary and Romania disrupted the Sality P2P botnet on Aug. 31, 2026, targeting infrastructure used to spread malware, conduct cyberattacks and steal cryptocurrency.
- The operation matters because more than 11 million unique IP addresses were associated with Sality during its existence, according to Europol.
- CrowdStrike estimated that Sality’s EggJagger component stole at least $150,000 in cryptocurrency.
The U.S. Department of Justice reported that the international operation involved authorities in the United States, Bulgaria, Hungary and Romania, with support from Europol and Eurojust. CrowdStrike and the Shadowserver Foundation also participated.
U.S. and European law enforcement seized domains linked to Sality. CrowdStrike specialists also conducted a sinkhole operation designed to isolate infected devices from the botnet’s operators.
According to Europol, more than 11 million unique IP addresses were associated with Sality’s infrastructure during its existence. At its peak, the operator could control as many as 1 million infected devices simultaneously. At the time of the operation, the network could distribute malware to more than 15,000 machines worldwide.
How Sality operated
Sality emerged in 2003 and evolved from a file-infector virus into a decentralized peer-to-peer botnet. Instead of relying on a centralized command-and-control server, infected devices exchanged commands directly with one another. That structure allowed the infrastructure to remain operational when individual nodes were taken offline.
The botnet distributed credential-stealing tools, proxy utilities and malware used for distributed denial-of-service attacks. Over the past eight years, one of its core components was EggJagger, a clipper that monitored copied Bitcoin and Ethereum wallet addresses and replaced them with addresses controlled by the attacker.
According to a CrowdStrike estimate, the Sality operator stole at least $150,000 in cryptocurrency through EggJagger. CrowdStrike said the estimate covered only EggJagger and excluded other sources of revenue associated with the botnet.
Specialists disrupted the network by exploiting a feature of its architecture. They removed active Sality nodes from infected devices’ peer lists and replaced them with controlled sinkhole servers, preventing the operator from sending new commands and malicious files to the bots.
Shadowserver is working with internet service providers and cyber incident response teams to identify remaining infected devices and notify their owners.
CrowdStrike believes Sality has Russian roots. The company said it reached that assessment by tracking the network’s likely operator, the cybercriminal group it calls SALTY SPIDER.
Since the beginning of 2025, total damage from cybersecurity incidents involving cryptocurrency platforms has amounted to $3.63 billion.
Source: Incrypted
