U.S. law-enforcement agencies and the cybersecurity firm CrowdStrike took down a 23-year-old Russia-based botnet on Monday.
Authorities from the Justice Department, the FBI and the Defense Criminal Investigative Service seized U.S.-based domain names belonging to the Sality botnet, while CrowdStrike analysts worked with the agencies to sever infected computers from the botnet. Investigators in Bulgaria, Hungary and Romania also took down Sality domain names in their jurisdictions.
Since 2003, Sality powered spam campaigns, credential-theft operations, distributed denial-of-service (DDoS) attacks and malicious proxy networks. In 2018, the botnet began deploying malware that hijacked cryptocurrency transactions by replacing copied wallet addresses with attacker-controlled ones.
Sality “has been one of the most persistent threats on the internet, not because of its payloads but because of the robustness of its architecture,” CrowdStrike said in its report on the botnet’s takedown.
Because Sality was a peer-to-peer botnet, it propagated through direct interactions between infected machines, rather than through interactions with a command-and-control server, which made it harder to shut down.
“This decentralised structure makes them particularly resilient and difficult to dismantle,” Europol said in a statement, “as disrupting individual parts of the infrastructure does not necessarily bring down the wider network.”
The malware powering the botnet was also adaptable, embedding itself in executable files on compromised systems and spreading through multiple forms of file transfers. “This meant infections regenerated continuously without requiring phishing campaigns, exploit kits, or any active effort from the operator,” CrowdStrike said.
Following the global takedown operation, machines still infected with Sality malware will ping computers controlled by CrowdStrike, enabling the security firm to identify compromised devices. The nonprofit Shadowserver Foundation will use that information to help internet service providers and national cybersecurity agencies locate those organizations and help them eliminate the malware.
Sality is the latest target of a coordinated global campaign by law enforcement and industry. Previous targets have included Raptor Train, Glassworm, Qakbot and KV. In March, the U.S. worked with Canada and Germany to dismantle four internet of things botnets that had collectively compromised more than three million devices.
Bill Essayli, an assistant U.S. attorney for the Central District of California, said in a statement that the Sality takedown showed that “by working together, the public and private sectors can be a powerful force for good.”

