Executive Summary

In September 2026, international law enforcement agencies including the FBI, DOJ, and European authorities successfully dismantled the Sality botnet infrastructure in a coordinated global operation. The peer-to-peer botnet, active for over two decades and controlled by the Russian cybercriminal group SALTY SPIDER, had infected more than 15,000 devices since 2003. The takedown involved seizing command and control domains across the US and Europe, while CrowdStrike's Counter Adversary Operations team executed a sinkhole operation to isolate infected machines and disrupt the botnet's communication backbone.

This takedown reflects the growing effectiveness of international cybercrime cooperation and highlights the persistent threat of long-running botnets that adapt their payloads over time, most recently focusing on cryptocurrency clipjacking attacks through EggJagger malware.

Why This Matters Now

The Sality takedown demonstrates how legacy botnets continue evolving their attack methods, particularly targeting cryptocurrency transactions, while showcasing the critical need for sustained international cooperation to combat persistent cyber threats that operate across decades.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Sality operated as a peer-to-peer botnet for over 20 years, making it resilient to takedowns, and evolved from credential theft to cryptocurrency clipjacking attacks that silently replaced wallet addresses in victims' clipboards.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have significantly constrained the Sality botnet's ability to propagate laterally and maintain persistent P2P communication across network segments. The segmentation and controlled egress capabilities would likely have reduced the botnet's operational reach and limited its cryptocurrency clipjacking impact.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The initial malware delivery may have succeeded on individual endpoints, but CNSF visibility would likely have detected the anomalous network behaviors and communication patterns early in the infection lifecycle

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: While local privilege escalation may have occurred on compromised endpoints, zero trust segmentation would likely have contained the malware's ability to access sensitive network resources and establish broader persistence mechanisms

Lateral Movement

Control: East-West Traffic Security

Mitigation: The P2P propagation mechanisms would likely have been severely constrained by east-west traffic controls, significantly reducing the botnet's ability to spread across network segments and recruit additional infected hosts

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The P2P super peer architecture would likely have faced significant operational constraints due to multicloud visibility detecting and blocking the distributed command infrastructure and coordinated payload distribution activities

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: While local clipboard monitoring may have continued, egress controls would likely have constrained the malware's ability to communicate replacement wallet addresses and coordinate clipjacking activities with external command infrastructure

Impact (Mitigations)

The overall cryptocurrency theft and DDoS capabilities would likely have been substantially diminished due to constrained peer communication, limited command coordination, and restricted access to target financial services

Impact at a Glance

Affected Business Functions

  • Cryptocurrency wallet management
  • Financial transaction processing
  • Network security operations
  • Data integrity protection
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Over 15,000 infected devices were part of the botnet infrastructure. The primary payload EggJagger performed clipjacking attacks, intercepting and replacing cryptocurrency wallet addresses to redirect funds to attacker-controlled wallets. No specific data breach amounts disclosed, but cryptocurrency theft operations were active for 8+ years.

Recommended Actions

  • Implement Zero Trust segmentation to prevent P2P botnet communication between workloads and limit lateral movement across network segments
  • Deploy egress security controls with FQDN filtering to block unauthorized outbound communications to botnet command and control infrastructure
  • Enable multicloud visibility and anomaly detection to identify suspicious P2P traffic patterns and repeated malformed requests indicative of botnet activity
  • Establish encrypted traffic inspection capabilities to detect malware payloads and clipjacking tools within network communications
  • Implement threat detection with behavioral baselining to identify anomalous clipboard monitoring activities and unauthorized cryptocurrency address substitution

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image