Home / Companies / Crowdstrike / Blog / Post Details
Content Deep Dive

Peer Pressure: Inside the Sality Botnet Disruption Operation

Blog post from Crowdstrike

Post Details
Company
Date Published
Author
CrowdStrike Counter Adversary Operations
Word Count
3,209
Company Posts That Month
5
Language
English
Hacker News Points
-
Post removed?
No
Summary

CrowdStrike reported that, on August 31, 2026, it worked with U.S. and international law enforcement agencies and industry partners to disrupt Sality, a peer-to-peer botnet that had operated for more than two decades and distributed malware to over 15,000 infected systems worldwide. First identified in 2003, Sality spread by infecting executable files and relied on decentralized peer communications rather than centralized command-and-control servers, making it unusually persistent; its recent primary payload, EggJagger, replaced cryptocurrency wallet addresses copied to victims’ clipboards, with CrowdStrike estimating at least 12.1 million rubles in stolen cryptocurrency. The operation manipulated the botnet’s peer lists to remove legitimate nodes and introduce sinkholes, cutting the operator off from infected machines and preventing delivery of new payload instructions, while authorities also took down active payload-hosting URLs. CrowdStrike notes that the disruption does not remove existing malware from compromised devices and advises organizations to use the published network indicators, URLs, and YARA detection rules to identify and remediate remaining infections.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
AI Agents 2 No monthly metrics for this publish month.
Zero Trust 2 No monthly metrics for this publish month.
Real-time 1 No monthly metrics for this publish month.
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.