Executive Summary
In September 2026, international law enforcement agencies including the FBI, DOJ, and European authorities successfully dismantled the Sality botnet infrastructure in a coordinated global operation. The peer-to-peer botnet, active for over two decades and controlled by the Russian cybercriminal group SALTY SPIDER, had infected more than 15,000 devices since 2003. The takedown involved seizing command and control domains across the US and Europe, while CrowdStrike's Counter Adversary Operations team executed a sinkhole operation to isolate infected machines and disrupt the botnet's communication backbone.
This takedown reflects the growing effectiveness of international cybercrime cooperation and highlights the persistent threat of long-running botnets that adapt their payloads over time, most recently focusing on cryptocurrency clipjacking attacks through EggJagger malware.
Why This Matters Now
The Sality takedown demonstrates how legacy botnets continue evolving their attack methods, particularly targeting cryptocurrency transactions, while showcasing the critical need for sustained international cooperation to combat persistent cyber threats that operate across decades.
Attack Path Analysis
The Sality botnet operated for over two decades using P2P architecture to distribute malware payloads, primarily EggJagger clipjacking malware in recent years. Initial compromise occurred through malware distribution vectors, establishing persistence on over 15,000 devices. The botnet leveraged P2P communication for command and control, distributed various payloads including credential theft and DDoS tools, and conducted cryptocurrency clipjacking attacks before being disrupted through international law enforcement sinkholing operations.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Sality malware infected devices through various distribution vectors including spam campaigns, exploit kits, and drive-by downloads to establish initial foothold on victim systems
MITRE ATT&CK® Techniques
Phishing
Command and Scripting Interpreter
Registry Run Keys / Startup Folder
Web Protocols
Native API
Credentials from Web Browsers
Stored Data Manipulation
Network Denial of Service
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Engineering Techniques for Secure Development
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.05
DORA – Identification
Control ID: Article 8
CISA ZTMM 2.0 – Device Security
Control ID: Function 2
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001 – Management of Technical Vulnerabilities
Control ID: A.12.6.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Banking/Mortgage
Sality botnet's clipjacking attacks directly target cryptocurrency transactions, threatening financial institutions' digital asset operations and client fund security mechanisms.
Information Technology/IT
P2P botnet infrastructure leveraging lateral movement capabilities poses significant risks to IT service providers managing multi-client environments and cloud infrastructures.
Computer/Network Security
Twenty-year Sality operation demonstrates advanced persistent threats requiring enhanced egress filtering, anomaly detection, and zero trust segmentation for cybersecurity providers.
Telecommunications
Botnet's proxy services and network exploitation capabilities threaten telecommunications infrastructure, requiring encrypted traffic monitoring and east-west traffic security controls.
Sources
- Sality botnet infrastructure dismantled in joint global takedownhttps://www.bleepingcomputer.com/news/security/sality-botnet-infrastructure-dismantled-in-joint-global-takedown/Verified
- Global public-private operation disrupts Sality botnet active for two decadeshttps://www.europol.europa.eu/media-press/newsroom/news/global-public-private-operation-disrupts-sality-botnet-active-for-two-decadesVerified
- Sality Malware Disrupted in International Cyber Takedownhttps://www.justice.gov/usao-cdca/pr/sality-malware-disrupted-international-cyber-takedownVerified
- Inside the Sality Botnet Disruption Operationhttp://www.crowdstrike.com/en-us/blog/inside-sality-botnet-disruption-operation/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly constrained the Sality botnet's ability to propagate laterally and maintain persistent P2P communication across network segments. The segmentation and controlled egress capabilities would likely have reduced the botnet's operational reach and limited its cryptocurrency clipjacking impact.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The initial malware delivery may have succeeded on individual endpoints, but CNSF visibility would likely have detected the anomalous network behaviors and communication patterns early in the infection lifecycle
Control: Zero Trust Segmentation
Mitigation: While local privilege escalation may have occurred on compromised endpoints, zero trust segmentation would likely have contained the malware's ability to access sensitive network resources and establish broader persistence mechanisms
Control: East-West Traffic Security
Mitigation: The P2P propagation mechanisms would likely have been severely constrained by east-west traffic controls, significantly reducing the botnet's ability to spread across network segments and recruit additional infected hosts
Control: Multicloud Visibility & Control
Mitigation: The P2P super peer architecture would likely have faced significant operational constraints due to multicloud visibility detecting and blocking the distributed command infrastructure and coordinated payload distribution activities
Control: Egress Security & Policy Enforcement
Mitigation: While local clipboard monitoring may have continued, egress controls would likely have constrained the malware's ability to communicate replacement wallet addresses and coordinate clipjacking activities with external command infrastructure
The overall cryptocurrency theft and DDoS capabilities would likely have been substantially diminished due to constrained peer communication, limited command coordination, and restricted access to target financial services
Impact at a Glance
Affected Business Functions
- Cryptocurrency wallet management
- Financial transaction processing
- Network security operations
- Data integrity protection
Estimated downtime: N/A
Estimated loss: N/A
Over 15,000 infected devices were part of the botnet infrastructure. The primary payload EggJagger performed clipjacking attacks, intercepting and replacing cryptocurrency wallet addresses to redirect funds to attacker-controlled wallets. No specific data breach amounts disclosed, but cryptocurrency theft operations were active for 8+ years.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust segmentation to prevent P2P botnet communication between workloads and limit lateral movement across network segments
- • Deploy egress security controls with FQDN filtering to block unauthorized outbound communications to botnet command and control infrastructure
- • Enable multicloud visibility and anomaly detection to identify suspicious P2P traffic patterns and repeated malformed requests indicative of botnet activity
- • Establish encrypted traffic inspection capabilities to detect malware payloads and clipjacking tools within network communications
- • Implement threat detection with behavioral baselining to identify anomalous clipboard monitoring activities and unauthorized cryptocurrency address substitution



