A botnet that predates the iPhone by four years just got sinkholed.
CrowdStrike, working with the DOJ, FBI, DCIS, Europol, Eurojust, and law enforcement in Bulgaria, Hungary, and Romania, disrupted Sality, a peer-to-peer botnet running since 2003. Unlike botnets that phone home to one server, Sality's roughly 15,000 infected endpoints talked to each other, which is why it survived this long. Since 2018, its main job has been spreading EggJagger, a clipboard hijacker that swaps copied crypto wallet addresses for the attacker's own. CrowdStrike says that trick alone netted its operators more than $150,000.
The takedown method matters as much as the target. Instead of seizing servers, researchers planted their own devices inside the botnet's peer network and used them to purge other nodes' peer lists, cutting off communication from the inside. They paired that with getting the URLs hosting Sality's malware payloads pulled, so infected machines can't fetch new instructions during the transition.
A 23-year survival streak is the real story here. Sality outlasted most of the malware families it once helped distribute, largely because decentralized architecture makes botnets annoying to kill piece by piece. CrowdStrike is careful to call this a disruption, not an eradication - sinkholing blinds infected machines rather than removing the infection, so any surviving endpoints with cached payload URLs could still cause trouble until cleanup finishes.