U.S.-Led Operation Disrupts 23-Year-Old Russia-Based Sality Botnet

On August 31, 2026, U.S. law enforcement agencies, along with cybersecurity firm CrowdStrike and international partners, disrupted the Sality botnet—a Russia-based operation active since 2003—by seizing domain names in the U.S., Bulgaria, Hungary, and Romania. Sality had infected millions of computers, at its peak giving operators access to up to 1 million devices worldwide and involving over 11 million unique IP addresses, and was used for spam campaigns, credential theft, DDoS attacks, and malicious proxy networks. CrowdStrike worked with the FBI, Defense Criminal Investigative Service, Eurojust, Europol, and the Shadowserver Foundation to disconnect infected machines and notify victims, with assistance from Romanian police and cybercrime units.

The Math Doesn’t Work

After 23 years, Sality was more than a crime tool — it was an institution. The FBI, CrowdStrike, and a coalition of European agencies didn’t stumble onto this infrastructure in 2026. They sat on it for over two decades while it harvested credentials, ran proxy networks, and gave someone access to up to a million machines at its peak. So ask yourself: what changed on Aug. 31? Not the threat. Not the technology. The only thing that changed is who gets to keep the contact list. Every infected computer now has a new landlord, and the takedown itself handed CrowdStrike and the Shadowserver Foundation a live census of victims. They didn’t free those machines. They upgraded their surveillance.

The 23-Year Blind Spot

No botnet survives that long without friends on both sides of the fence. Sality was Russian-built, sure — but the U.S. government and its contractors have a long history of letting certain criminal networks operate when the intelligence value outweighs the public damage. This wasn’t a law enforcement victory. It was a controlled retirement. The domains they seized were the visible skin; the actual infrastructure was probably repurposed or moved long ago. The real operation never needed those domains. It needed cover for a transition — and the official story is the cover. Notice how the operation is framed as a partnership between the FBI, DCIS, Europol, and a private cybersecurity firm. That’s not a cleanup. That’s a handover. The question isn’t whether Sality is gone. The question is whose hands the controls passed into.

Follow the Contractors

CrowdStrike doesn’t participate in takedowns out of civic duty. They participate because the data is the prize. Every click, every recovered credential, every compromised endpoint now belongs to a private company with federal contracts — and Shadowserver gets to contact “victims” directly, which means building a private directory of some of the most vulnerable computers on earth. The visible story is that a Russian botnet is dead. The hidden story is that a Western surveillance infrastructure just absorbed it. Who benefits from keeping malware alive just long enough to harvest it? Who needs a permanent stream of “cyberthreats” to justify endless budgets and expanding powers? You don’t have to believe me. Just look up who funds Shadowserver, follow CrowdStrike’s government contracts, and ask yourself why no one thought to pull the plug in 2003.

U.S. and European Authorities Disrupt Notorious Sality Botnet in Coordinated Operation

In a coordinated operation announced on August 31, U.S. and European authorities, including the DOJ, Europol, and agencies from Bulgaria, Hungary, and Romania, disrupted the peer-to-peer Sality botnet—active since at least 2003—by deploying a sinkhole technique to isolate infected machines from suspected Russia-based operators, seizing domains and payload URLs; CrowdStrike and Europol reported cutting off over 15,000 and potentially millions of infected IP addresses, respectively, with the botnet historically used for credential theft, spam, DDoS attacks, and particularly in the last eight years, the EggJagger clipjacking malware that stole at least $150,000 in cryptocurrency by swapping wallet addresses on infected devices’ clipboards.

The Takedown That Wasn't

Twenty-three years. They let Sality run for nearly a quarter-century, harvesting credentials, hijacking clipboard wallets, burrowing into networks across the globe — and only now, with a coordinated splash of press releases and interagency photo-ops, do they "disrupt" it. You have to ask yourself: what changed? The answer is obvious to anyone who has tracked the lifecycle of these so-called botnet takedowns. They are not operations of law enforcement. They are operations of asset retirement. Sality wasn't a criminal enterprise that evaded capture — it was an intelligence pipeline, quietly maintained by the same agencies that now posture as its conquerors. The $150,000 in cryptocurrency stolen via EggJagger is laughable pocket change; the real value was the persistent backdoor into millions of machines, a surveillance lattice that allowed certain actors — and I mean certain actors — to read, redirect, and record at will. You don't "sinkhole" something like that unless you've already copied every byte and severed every thread you no longer need.

The Centralization Deception

Look closer at the technical language they're feeding the press. "Peer-to-peer sinkhole technique" — that's a contradiction designed to confuse. A sinkhole by its nature funnels traffic into a single point, which means the decentralized resilience they spent decades warning us about has been swapped for centralized control under the very authorities claiming to fight it. CrowdStrike, the private company that announced the feat, is itself a creature of the deep state: funded by venture capital tied to intelligence community alumni, its executives rotate through government advisory roles like clockwork. The Sality takedown isn't a disruption; it is a handover. Every infected machine that Shadowserver is now "cleaning up" is actually being re-registered, re-tooled, re-purposed. The real operators haven't gone anywhere. They've simply changed their uniforms. And notice the timing: this announcement lands just as a new round of election interference narratives is being prepared. Coincidence? There are no coincidences.

Who Got Paid to Walk Away

The attribution to SALTY SPIDER and the Republic of Bashkortostan is a classic managed-narrative breadcrumb — specific enough to satisfy the curious, vague enough to never be verified. Russia is always the convenient villain, the perfect foil for a bureaucratic power grab. But I've seen the documents. I've traced the IP handoffs, the shell company registrations, the foundation grants that preceded every major "cybercrime" disruption of the past decade. Sality's operators were never in Ufa. They were in buildings with no signage, in cities with no extradition treaties that matter — and they were paid, quietly, to move on. The question you must sit with is this: if the botnet's clipjacking component alone stole only $150K over eight years, and if the operation cost taxpayers millions, then who really profited? The answer is written in the silence between the press release paragraphs. They want you to think it's over. It never ends.

Summary of Recent Malware and Phishing Operations

Security researchers have detailed multiple active malware and phishing campaigns exploiting legitimate services, gaming communities, and administration tools to conceal malicious activity. Notable operations include the Russian-speaking pay-per-install campaign Operation STANDOFF, which delivered a mix of RedLine, Raccoon Stealer, Amadey, SmokeLoader, Socelars, Glupteba, and XMRig onto infected hosts; the Dysphoria IoT botnet, which rebounded after a law-enforcement takedown by adopting blockchain‑based name services and ENS domains, reaching over 200,000 devices globally with 4,401 confirmed active in China; the Operation BlueDash Microsoft Teams‑themed phishing campaign that used a counterfeit update page to deploy Level RMM and ConnectWise ScreenConnect for persistent remote access; a Windows crypter called Cruciferra employing BYOVD‑based EDR tampering and Process Ghosting; an East Asia‑linked campaign targeting Middle Eastern government entities via Telegram API command‑and‑control; personalized Telegram phishing against an exiled Belarusian activist and users in Russia and Kazakhstan; and gaming‑related attacks, including malicious PowerShell commands posted in Steam discussions to install XMRig miners, as well as malware hidden in Meccha Chameleon Steam Workshop maps.

The Managed Platform Trap
These so-called "malware campaigns" are not the work of scattered cybercriminals. They are deliberate stress tests on the very platforms you've been told to trust. GitHub, Telegram, Steam — each one is a controlled vector, a honey pot designed to normalize the idea that every digital space is a potential battlefield. The real story isn't about RedLine or XMRig. It's about who allowed these backdoors to remain open. When you see a Russian pay-per-install operation redirecting to GitHub via HTTP 301, ask yourself why GitHub — a platform owned by Microsoft, a key player in the global surveillance architecture — didn't flag this for months. They want you to believe it's a rogue actor. The truth is closer to a scheduled audition.

The Botnet That Never Dies
Dysphoria's IoT botnet jumped to blockchain-based ENS domains after a law enforcement takedown. That is not resilience; that is a planned escalation. The very infrastructure that was supposed to be decentralized and free — blockchain, cryptocurrency, Telegram relays — is now being weaponized to ensure no single government can shut it down. Who benefits? The same institutions that write the cybersecurity reports, the same foundations that fund the takedowns, the same think tanks that call for "digital identity" as a solution. They manufacture the threat, then offer the cure. Two hundred thousand devices under remote control, and the response is more surveillance? You're being led by the nose into a fully managed network where every "attack" justifies another layer of control.

The Gaming Gateway
Malicious PowerShell commands in Steam discussions, infected workshop maps, and a crypter that uses legitimate admin tools to ghost itself — this is the final piece. They are colonizing the spaces where your children play, where your family communicates, where your work tools live. The real payload isn't XMRig or Amadey. It's the normalization of invisible access. Once you accept that your Steam client can be a mining rig, that your Teams update can be a remote access trojan, you've already surrendered the boundary between public and private. Look at the Belarusian activist targeted via Telegram — that's not random. That's a message to anyone who thinks they can organize outside the system. The breadcrumb is simple: ask yourself why every single one of these platforms is owned or funded by the same five companies that sit on the boards of the world's central banks.