logo

Sality botnet infrastructure dismantled in joint global takedown

ID: 8f0d347f-67a6-5164-bf02-7f8990c3238c

STIX ID: report--8f0d347f-67a6-5164-bf02-7f8990c3238c

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-09-02

Date Updated: 2026-09-10

Author: Sergiu Gatlan

...
...

International law enforcement and private partners, including the DOJ, FBI, Europol, Eurojust, and CrowdStrike, conducted a coordinated operation to seize Sality-related domains and sinkhole the botnet's P2P super peers, disrupting two active Sality networks that had been used for over two decades to deliver various malware families. CrowdStrike attributes the botnet to a criminal group tracked as SALTY SPIDER and notes primary recent use for EggJagger clipjacking (clipboard replacement of cryptocurrency addresses); the action isolated infected machines and removed operator control.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.