CrowdStrike and the FBI Dismantling Sality After 23 Years
Sality has been sending spam and stealing cryptocurrency for 23 years. The takedown method was to lie to it.
September 2, 2026 – 10:27 am
CrowdStrike Holdings, Inc. is an American cybersecurity technology company. Credit: bluestork via Shutterstock.com
Sality has been infecting computers since 2003, making it older than the iPhone, Facebook, and much of the security industry now working to dismantle it. US law enforcement and CrowdStrike began taking it apart this week, according to Reuters.
For more than two decades, the operation has been used for fairly ordinary cybercrime. Infected machines have been used to send spam, launch distributed denial-of-service attacks, and steal cryptocurrency, with the criminals shifting between them as different opportunities became profitable.
The way authorities took it down is more unusual. CrowdStrike reverse-engineered the botnet, identified weaknesses in its structure, and then seeded it with false information that convinced infected machines to disconnect from their controller.
“This was the most complex botnet takeover we have ever done,” said Tillmann Werner, a CrowdStrike researcher. The company announced the operation at its Day Zero threat intelligence summit in Las Vegas.
Sality managed to survive for so long partly because of how it was designed. It spread by infecting executable files rather than depending on a single command server, while its peer-to-peer structure meant there was no central machine that could simply be taken offline to bring down the rest.
US authorities handled the legal side of the operation. The FBI and Justice Department seized the web domains used to control infected machines, removing part of the infrastructure while CrowdStrike worked to break the remaining connections.
“Cybercriminals, botnets, and malware are a clear and present danger,” said Bill Essayli, first assistant United States attorney.
David Watson of the Shadowserver Foundation described Sality as a way into a large number of organizations. That helps explain why a 23-year-old botnet is still worth dismantling. Sality’s value was not necessarily what it could do itself, but the access it provided to compromised networks, which could then be sold or used for other attacks.
The problem is not limited to the countries named in the announcement. Old infections remain a risk in Europe too, where industrial systems, small business servers, and public sector machines can still be running software old enough to be vulnerable to malware written in 2003.
The longevity of an infection says as much about the victims as it does about the attackers. Machines can remain compromised for years because nobody notices, nobody patches them, or the software continues running on systems that their owners rarely think about anymore.
Takedowns like this do not necessarily lead to arrests, and none have been announced in this case. When the operators are outside the reach of the courts carrying out the action, seizing infrastructure and cutting off connections are among the few options available.
Private security companies taking a more active role is also becoming increasingly common. The US has now authorized private companies to run cyber operations abroad, and CrowdStrike’s use of false data inside a criminal network sits close to that evolving boundary between cybersecurity and offensive operations.
There is no guarantee the takedown will be permanent. Botnets have been dismantled and rebuilt before, and the computers being disconnected today still contain remnants of Sality’s code.