A 23-year-old botnet just lost its network the way it built one: peer by peer. CrowdStrike’s Counter Adversary Operations team, working with the US Department of Justice, FBI, the Defense Criminal Investigative Service and law enforcement in Bulgaria, Hungary and Romania, ran a sinkhole operation on August 31 that stripped legitimate peers from the Sality botnet’s peer-to-peer address lists and replaced them with sinkhole entries, cutting off more than 15,000 infected machines worldwide from new commands.
Sality has been active since at least 2003 and is attributed by CrowdStrike to a group it tracks as SALTY SPIDER, likely operating out of Russia’s Republic of Bashkortostan. For the past eight years its main payload has been EggJagger, a clipboard hijacker that watches for copied Bitcoin or Ethereum wallet addresses and silently swaps in an attacker-controlled address before a victim completes a payment, a tactic CrowdStrike estimates netted the operator at least 150,000 dollars.
The operational detail worth noting is what made Sality hard to kill for two decades: its peer-to-peer design meant there was no central command server to seize. This takedown did not seize a server. It rewrote the botnet’s own address book against it, the same peer-poisoning approach used against GameOver Zeus and Kelihos, which suggests the durable defense against P2P malware is understanding its protocol well enough to speak it back rather than finding its infrastructure. CrowdStrike put it plainly: the operation “demonstrates that P2P architecture, long considered a shield against disruption, is not invincible.”
Security teams that flagged Sality infections years ago and moved on should not assume the threat ended with detection. Endpoints still carrying the Sality file infector should be checked for residual EggJagger activity, since the clipboard-hijacking payload operated independently of whether the broader botnet’s command channel was still live. The takedown follows the same infrastructure-first logic that dismantled another self-propagating threat by attacking its propagation mechanism, and the same public-private model used when law enforcement moved against alleged hacking crews earlier this year.
Source: CrowdStrike