A 23-Year-Old Botnet Was Tricked Into Cutting Off Its Own Computers
A coordinated operation disrupted Sality by poisoning the peer lists used by more than 15,000 infected computers, separating them from their operator. The 23-year-old botnet is no longer controlled by its creator, but victim machines still require cleanup and the unidentified operator could try to rebuild it.
A multinational operation has disrupted Sality, a malware network that survived for 23 years by letting infected computers exchange commands directly. Investigators did not simply switch off a central server. They manipulated the peer lists that each infected machine used to understand the network, gradually separating the bots from their operator.
The 30-second summary
- What happened? CrowdStrike, US agencies and European partners isolated more than 15,000 Sality-infected machines and seized related domains.
- Why does it matter? The operation shows that even a decentralized peer-to-peer botnet can be disrupted when defenders understand its communication protocol closely enough.
- What is the catch? Disruption blocks the operator's command channel, but it does not automatically remove the malware from every victim computer or identify its creator.
A network built without one obvious switch
Sality first appeared in 2003 as malware that infected executable files. It later evolved into two peer-to-peer networks whose compromised computers passed commands among themselves instead of relying on one central command server. That design removed the single target that investigators normally seize to disable a botnet.
The malware could spread through shared folders, removable drives and file sharing. It then delivered additional tools for credential theft, spam, proxy services, network attacks and distributed denial-of-service campaigns. CrowdStrike says its main payload during the past eight years, EggJagger, watched computer clipboards and replaced copied cryptocurrency addresses with wallets controlled by the attacker.
Key number: More than 15,000 infected machines were receiving malicious payloads through Sality before the disruption, according to CrowdStrike.
How defenders poisoned Sality's map
Each infected computer kept a list of publicly reachable “super peers” that helped it find the rest of the network. The bots checked those entries roughly every 40 minutes and removed peers that stopped responding. CrowdStrike says the operation exploited that maintenance behavior by inserting purpose-built sinkhole entries and removing legitimate super peers from the lists.
The false network information caused increasing numbers of bots to connect to defender-controlled infrastructure instead of the criminal operator. At the same time, the US Justice Department, FBI and Defense Criminal Investigative Service seized Sality-linked domains, while authorities in Bulgaria, Hungary and Romania acted against European domains.
Why this operation differs from a domain seizure
Taking domains can cripple services that depend on them, as happened when US authorities recently disabled hacking platforms concealed behind infected routers. Sality's peer-to-peer command system was harder because the infected machines could continue sharing instructions without a conventional central server.
The Shadowserver Foundation is now helping internet providers and incident-response teams identify victims and support cleanup. That stage matters because an isolated machine still contains malicious files and may remain vulnerable to other attackers.
Before we overstate the result
CrowdStrike says Sality is no longer under its operator's control, but the unnamed creator has not been arrested and could attempt to rebuild infrastructure. The reported 15,000 machines reflects CrowdStrike's visibility, not necessarily every historical infection. The operation also blocks communication rather than remotely disinfecting victim computers. Device owners and network administrators still need notification, investigation and remediation.
What comes next
The technical test is whether the sinkhole remains dominant as infected machines refresh their peer lists and whether the operator tries to distribute a replacement network. For defenders, Sality provides a reusable lesson: a decentralized design may remove a central weakness, but the protocol that keeps peers connected can become a different point of intervention.
Verified topics and entities
Sources and citations4 sources
External references used to support the reporting in this article.
Published by
NewTqnia Technology Policy Desk
An institutional editorial team within NewTqnia