Sality P2P Botnet Dismantled After 23 Years by CrowdStrike, FBI, DOJ, and a Europol-Led International Coalition — Threadlinqs Intelligence
As of 2026-09-02, Sality P2P Botnet Dismantled After 23 Years by CrowdStrike, FBI, DOJ, and a Europol-Led International Coalition is a medium-severity malware threat attributed to SALTY SPIDER (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 18 indicators of compromise.
Threat ID: TL-2026-2303 · Severity: MEDIUM · Status: MONITORING · Category: MALWARE
Attribution: SALTY SPIDER · Russia · FINANCIAL
CrowdStrike's Counter Adversary Operations team, working with the FBI, DOJ/DCIS, Europol, Eurojust, the Shadowserver Foundation, and authorities in Bulgaria, Hungary, and Romania, dismantled the
Sality is a polymorphic, Windows-executable-infecting virus first identified in 2003 and operated continuously for 23 years by an eCrime group CrowdStrike tracks as SALTY SPIDER (aliases: KuKu, SalLoad, Kookoo, SaliCode, Kukacka), assessed to be based in the Republic of Bashkortostan, Russia. After 2008 its original centralized model was superseded by advanced peer-to-peer (P2P) variants that removed any single command server an investigator could take down, and the botnet later split into two independent, cryptographically incompatible networks (v3 and v4) run by the same operator. A mid-2017 surge in infections coincided with exploitation of the EternalBlue SMBv1 vulnerability (CVE-2017-0144), the same flaw behind WannaCry and NotPetya, which CrowdStrike credits with driving new Sality infections. Historically, Sality-infected machines were monetized through credential theft, spam distribution, proxy services, and DDoS-for-hire capability; the botnet's DDoS function was weaponized at least three times: against the Arabic-language financial forum forex2030.com in April 2016, against the Ukrainian forum kharkovforum.com one day after Russia's February 2022 invasion of Ukraine (apparently to suppress military-related discussion), and against the Russian cryptocurrency exchange AvanChange in September 2023 using a payload compiled only seconds before deployment.
For roughly the past eight years, Sality's primary payload has been EggJagger, a clipboard-hijacking ('clipjacking') tool that silently monitors infected machines for copied Bitcoin and Ethereum wallet addresses and substitutes an attacker-controlled address, redirecting the victim's intended payment. CrowdStrike attributes at least ₽12.1 million (~$150,000 USD) in confirmed theft to EggJagger, with the operator's unspent cryptocurrency holdings peaking at roughly ₽147 million (~$1.35M nominal, ~$4M at Western purchasing-power parity) in January 2025 — notably, most of the stolen funds were never moved or cashed out.
On August 31, 2026, CrowdStrike executed what its researcher Tillmann Werner called the company's most complex botnet takeover to date. Sality's P2P protocol had no authentication or cryptographic identity verification, meaning any machine that correctly answered the P2P handshake was trusted and added to a bot's list of 'super peers' — the publicly reachable infected machines that form the network's backbone. Every bot re-verifies its super-peer list roughly every 40 minutes, dropping unresponsive entries. CrowdStrike exploited this maintenance cycle — a technique with precedent in the GameOver Zeus (2014) and Kelihos (2017) takedowns — to progressively remove legitimate super peers from bots' lists and inject sinkhole nodes in their place, cutting off URL/file-pack distribution to the wider network. For machines behind NAT/firewalls that could not be reached directly, the operation passively purged their peer lists whenever they contacted a sinkhole during a routine maintenance cycle. Simultaneously, the DOJ, FBI, and DCIS seized Sality-linked domains hosted in the U.S., while Bulgarian, Hungarian, and Romanian authorities seized additional domains hosted in Europe, with the Shadowserver Foundation working with ISPs to identify and support remediation of the remaining roughly 15,000 infected machines worldwide. No arrests or indictments were announced, and the SALTY SPIDER operators remain publicly unidentified.
Target sectors: financial services, online forums and communities
Target regions: Global, romania, venezuela, ukraine, Middle East
Timeline
- Sality is first identified as a centralized, polymorphic, Windows-executable-infecting virus; SALTY SPIDER begins operating it as a botnet.
- Sality's original centralized model is superseded by advanced peer-to-peer (P2P) variants, removing any single command server that investigators could take down.
- The Sality botnet is weaponized for a DDoS attack that renders the Arabic-language financial forum forex2030.com unresponsive.
- CrowdStrike observes a surge in Sality v3/v4 infections beginning summer 2017, coinciding with exploitation of the EternalBlue SMBv1 vulnerability (CVE-2017-0144).
- CrowdStrike Intelligence observes SALTY SPIDER distributing cryptocurrency-clipper malware via Sality, beginning what becomes roughly eight years of EggJagger as the botnet's primary payload.
- One day after Russia's invasion of Ukraine begins, Sality operators DDoS the Ukrainian discussion forum kharkovforum.com, apparently to suppress military-related discussion.
- Sality operators launch a DDoS attack against the Russian cryptocurrency exchange AvanChange using a payload compiled only seconds before deployment.
- EggJagger's unspent stolen-cryptocurrency holdings peak at approximately ₽147 million (~$1.35M nominal, ~$4M at purchasing-power parity); most of the funds are never cashed out.
- CrowdStrike, the FBI, DOJ/DCIS, Europol, Eurojust, Shadowserver, and Bulgarian, Hungarian, and Romanian authorities execute the coordinated takedown: peer-list poisoning isolates infected machines from Sality's P2P network while U.S. and European authorities seize Sality-linked domains.
- CrowdStrike, the DOJ, and law enforcement partners publicly announce the Sality botnet disruption; CrowdStrike researcher Tillmann Werner calls it the company's most complex botnet takeover to date.
Detections & IOCs
As of 2026-09-03, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 18 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, MEDIUM, threat intelligence, cybersecurity, CVE-2017-0144, T1091, T1566.001, T1204.002, T1554, T1027, T1685, T1014, T1056.001, T1555.003, T1090