CrowdStrike, the DOJ, and law enforcement in Bulgaria, Hungary, and Romania disrupted the Sality peer-to-peer botnet on August 31, more than 15,000 known infected machines were still active worldwide after 23 years of continuous operation since 2003. The takedown turned Sality’s own design against it, replacing trusted peers in the network with sinkholes since infected machines never verified who they were talking to, while the botnet’s most recent payload, a clipboard-hijacking tool called EggJagger, had stolen at least $150,000 in crypto by swapping in attacker wallet addresses.
More info here: Sality botnet infrastructure dismantled in joint global takedown
John Watters, Chairman & CEO, iCOUNTER Had This To Say:
“Twenty-three years is the real headline here. Sality launched in 2003 and outlived multiple generations of malware, multiple law enforcement agents and investigations, and multiple waves of the industry declaring old-school botnets dead. That kind of longevity only happens when a piece of malware keeps finding a new business model. Sality started as a generalist infector and spent its last eight years running EggJagger, quietly swapping cryptocurrency addresses on infected machines. Fifteen thousand known infected machines and $150,000 in known stolen crypto is small by today’s ransomware standards, but the operation didn’t need to be big. It needed patience, and it had it for over two decades.
CrowdStrike didn’t seize a server or arrest an operator. They turned Sality’s own architecture against it, replacing trusted peers in the network with sinkholes, because infected machines never verified who they were talking to in the first place. Shadowserver notified victims through ISPs and CSIRTs, and the DOJ coordinated the legal side with counterparts in Bulgaria, Hungary, and Romania. That combination is why this takedown is likely to hold instead of the infrastructure just resurfacing somewhere else in six months.
Sinkholing stops new instructions from reaching infected machines. It doesn’t clean them. Fifteen thousand known systems are still infected, just quiet now, and that remediation gap is going to outlast this week’s headlines.”
This illustrates that hackers can live for years in a system. Which means that you have to be constantly looking for them to achieve the best results.
Related
This entry was posted on September 2, 2026 at 2:04 pm and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
23-year-old Sality botnet finally taken down
CrowdStrike, the DOJ, and law enforcement in Bulgaria, Hungary, and Romania disrupted the Sality peer-to-peer botnet on August 31, more than 15,000 known infected machines were still active worldwide after 23 years of continuous operation since 2003. The takedown turned Sality’s own design against it, replacing trusted peers in the network with sinkholes since infected machines never verified who they were talking to, while the botnet’s most recent payload, a clipboard-hijacking tool called EggJagger, had stolen at least $150,000 in crypto by swapping in attacker wallet addresses.
More info here: Sality botnet infrastructure dismantled in joint global takedown
John Watters, Chairman & CEO, iCOUNTER Had This To Say:
“Twenty-three years is the real headline here. Sality launched in 2003 and outlived multiple generations of malware, multiple law enforcement agents and investigations, and multiple waves of the industry declaring old-school botnets dead. That kind of longevity only happens when a piece of malware keeps finding a new business model. Sality started as a generalist infector and spent its last eight years running EggJagger, quietly swapping cryptocurrency addresses on infected machines. Fifteen thousand known infected machines and $150,000 in known stolen crypto is small by today’s ransomware standards, but the operation didn’t need to be big. It needed patience, and it had it for over two decades.
CrowdStrike didn’t seize a server or arrest an operator. They turned Sality’s own architecture against it, replacing trusted peers in the network with sinkholes, because infected machines never verified who they were talking to in the first place. Shadowserver notified victims through ISPs and CSIRTs, and the DOJ coordinated the legal side with counterparts in Bulgaria, Hungary, and Romania. That combination is why this takedown is likely to hold instead of the infrastructure just resurfacing somewhere else in six months.
Sinkholing stops new instructions from reaching infected machines. It doesn’t clean them. Fifteen thousand known systems are still infected, just quiet now, and that remediation gap is going to outlast this week’s headlines.”
This illustrates that hackers can live for years in a system. Which means that you have to be constantly looking for them to achieve the best results.
Share this:
Like this:
Related
This entry was posted on September 2, 2026 at 2:04 pm and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.