The Department of Justice has confirmed a coordinated international takedown of the Sality botnet, a peer-to-peer malware network that has plagued victims worldwide since 2003.
The operation spanned the United States, Bulgaria, Hungary, and Romania, bringing together federal law enforcement and private-sector cybersecurity firms to dismantle infrastructure that had quietly powered cryptocurrency theft and cyberattacks for more than two decades.
FBI and CrowdStrike Disrupt Sality Botnet After 20 Years
Key to the disruption, as confirmed by the U.S. Department of Justice announcement, was the close cooperation between the DOJ, FBI, the Department of Defense’s Defense Criminal Investigative Service (DCIS), and private industry partners CrowdStrike and the Shadowserver Foundation.
Officials framed the effort as an early example of the first pillar of the Trump administration’s Cyber Strategy for America, which calls on agencies to “shape adversary behavior” by working alongside private companies to degrade criminal tools and infrastructure rather than pursuing enforcement alone.
First Assistant United States Attorney Bill Essayli said the takedown demonstrates that “the public and private sectors can be a powerful force for good” against botnets and malware, which he called “a clear and present danger to our nation’s security and economy.”
FBI Los Angeles Assistant Director in Charge Patrick Grandy added that the collaboration strengthens the Bureau’s capacity to neutralize threats like Sality, while DCIS Special Agent in Charge Kenneth DeChellis emphasized the operation’s importance to protecting the Department of Defense Information Network.
Unlike botnets that rely on centralized command-and-control servers, Sality functioned as a decentralized peer-to-peer network, allowing infected machines, or “bots,” to communicate directly with one another and pass along commands without a single point of failure.
This architecture made the malware notably resilient to takedown attempts over the years. Most owners of compromised devices had no idea their systems had been hijacked and folded into the botnet’s operations.
| Operation Parameter | Technical Details | Law Enforcement & Strategic Impact |
| Malware Profile | Sality P2P malware network (active since 2003) | 20+ years of cryptocurrency theft and distributed attacks |
| Network Architecture | Decentralized peer-to-peer protocol | Eliminates single points of failure to resist infrastructure takedowns |
| Compromise Footprint | 15,000+ active infected systems globally | Covert peer communication without device owners’ awareness |
| Disruption Technique | P2P sinkholing & multi-national domain seizures | CrowdStrike sinkhole severed peer traffic from criminal controllers |
| Coordinating Agencies | DOJ, FBI, DCIS, CrowdStrike, Shadowserver | Cross-border task force across US, Bulgaria, Hungary, and Romania |
The disruption unfolded this week when CrowdStrike’s Counter Adversary Operations team executed a peer-to-peer sinkhole, effectively rerouting botnet traffic away from criminal control.
Simultaneously, the DOJ, FBI, and DCIS seized Sality-linked domains inside the United States, while law enforcement agencies in Bulgaria, Hungary, and Romania moved against related domains hosted across Europe.
The Shadowserver Foundation is now working with internet service providers and national Computer Security Incident Response Teams to identify remaining infections and support victim notification and remediation.
The case drew support from Bulgaria’s General Directorate Combating Organized Crime, Hungary’s National Bureau of Investigation Cybercrime Department, Romania’s Central Cybercrime Unit, Eurojust, and Europol, alongside the DOJ’s Office of International Affairs.
Assistant United States Attorney Lauren Restrepo of the National Security Division led prosecution efforts alongside the FBI’s Los Angeles Field Office and DCIS.
With more than 15,000 systems reportedly still infected at the time of takedown, the operation marks one of the most significant actions against a long-running P2P botnet in recent years, and signals growing willingness by federal agencies to lean on private-sector threat intelligence to dismantle persistent cybercrime infrastructure.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
The post FBI and CrowdStrike Disrupt 20-Year-Old Sality Botnet Controlling 15,000+ Infected Systems appeared first on Cyber Security News.
