International law enforcement agencies and private partners have seized Sality malware infrastructure in a joint action aiming to disrupt and take down the peer-to-peer (P2P) botnet.
As part of this operation, supported by Europol and Eurojust, the U.S. Department of Justice (DOJ), FBI, and DCIS seized Sality-linked domains in the United States, while authorities in Bulgaria, Hungary, and Romania seized additional Sality-linked domains hosted in Europe.
CrowdStrike's Counter Adversary Operations team, in collaboration with international law enforcement and private industry partners, also dismantled the botnet's control channels in a peer-to-peer sinkhole operation that isolated infected machines.
The Sality botnet has been active for more than two decades and has infected over 15,000 devices with malware since at least 2003, when it first surfaced. CrowdStrike says Sality is controlled by a criminal group it tracks as SALTY SPIDER, which is likely operating out of the Republic of Bashkortostan in Russia.
"The victim computers infected with Sality were part of a peer-to-peer (P2P) botnet, which is a network of computers (each a 'bot) infected with the Sality malware and controlled by the Sality operator," the DOJ said.









