
US and European law enforcement agencies have disrupted the long-running Sality malware operation, cutting its operators off from more than 15,000 infected computers worldwide.
The coordinated action, carried out on August 31, involved the US Department of Justice, FBI, Defense Criminal Investigative Service (DCIS), CrowdStrike, the Shadowserver Foundation, and Europol.
CrowdStrike’s Counter Adversary Operations team said investigators neutralized Sality through a peer-to-peer sinkholing operation that manipulated the botnet’s own networking mechanism, isolating infected systems from infrastructure controlled by the malware operator.
First observed in 2003, Sality is a polymorphic file-infecting malware family that spreads by attaching itself to executable files and propagating through network shares, removable drives, and file-sharing activity. Unlike conventional botnets that rely on centralized command-and-control servers, Sality evolved into a decentralized peer-to-peer network in which infected computers communicated directly with one another.
That architecture helped Sality survive takedown attempts for more than two decades. Two separate networks, known as versions 3 and 4, remained active until this week's operation.
Sality itself primarily acted as a malware delivery platform. Over the years, operators used it to install credential stealers, spam tools, proxies, network exploitation malware, and distributed denial-of-service tools.
For roughly the past eight years, its main payload was EggJagger, a clipboard-hijacking malware that detects copied Bitcoin and Ethereum wallet addresses and replaces them with addresses controlled by the attacker.
CrowdStrike estimates EggJagger stole at least 12.1 million rubles, approximately $150,000, in cryptocurrency. The value of cryptocurrency held in associated wallets reportedly peaked at roughly 147 million rubles in January 2025.

CrowdStrike
Researchers also linked Sality to several DDoS incidents, including attacks against an Arabic-language financial forum in 2016, a Ukrainian web forum discussing Russia's invasion of Ukraine in February 2022, and Russian cryptocurrency exchange AvanChange in 2023.
Turning Sality's P2P network against it
The disruption exploited a weakness in Sality's peer-management protocol.
Each infected computer maintains a finite list of publicly reachable “super peers” and periodically checks whether those systems remain online. CrowdStrike and its partners manipulated those lists to remove legitimate Sality peers and replace them with controlled sinkhole servers.
Because Sality performs no authentication of peers joining the network, the sinkholes could appear as legitimate participants. Infected systems gradually became isolated from the operator and could no longer receive new payload download instructions or malware files.

CrowdStrike
Authorities also seized Sality-related domains in the United States, while investigators in Bulgaria, Hungary, and Romania acted against additional infrastructure hosted in Europe.
Shadowserver is now working with internet providers and incident response teams to identify affected systems and notify victims.
CrowdStrike warned that disruption of the command channel does not remove malware already installed on compromised machines.
Network defenders can check for UDP connections to the sinkhole address 188.166.101[.]148, which confirms a Sality infection. Organizations should also scan systems using the published Sality v3 and v4 YARA rules and review connections to the disclosed payload URLs.







Leave a Reply