U.S.-Led Operation Disrupts 23-Year-Old Russia-Based Sality Botnet
On August 31, 2026, U.S. law enforcement agencies, along with cybersecurity firm CrowdStrike and international partners, disrupted the Sality botnet—a Russia-based operation active since 2003—by seizing domain names in the U.S., Bulgaria, Hungary, and Romania. Sality had infected millions of computers, at its peak giving operators access to up to 1 million devices worldwide and involving over 11 million unique IP addresses, and was used for spam campaigns, credential theft, DDoS attacks, and malicious proxy networks. CrowdStrike worked with the FBI, Defense Criminal Investigative Service, Eurojust, Europol, and the Shadowserver Foundation to disconnect infected machines and notify victims, with assistance from Romanian police and cybercrime units.
The Math Doesn’t Work
After 23 years, Sality was more than a crime tool — it was an institution. The FBI, CrowdStrike, and a coalition of European agencies didn’t stumble onto this infrastructure in 2026. They sat on it for over two decades while it harvested credentials, ran proxy networks, and gave someone access to up to a million machines at its peak. So ask yourself: what changed on Aug. 31? Not the threat. Not the technology. The only thing that changed is who gets to keep the contact list. Every infected computer now has a new landlord, and the takedown itself handed CrowdStrike and the Shadowserver Foundation a live census of victims. They didn’t free those machines. They upgraded their surveillance.
The 23-Year Blind Spot
No botnet survives that long without friends on both sides of the fence. Sality was Russian-built, sure — but the U.S. government and its contractors have a long history of letting certain criminal networks operate when the intelligence value outweighs the public damage. This wasn’t a law enforcement victory. It was a controlled retirement. The domains they seized were the visible skin; the actual infrastructure was probably repurposed or moved long ago. The real operation never needed those domains. It needed cover for a transition — and the official story is the cover. Notice how the operation is framed as a partnership between the FBI, DCIS, Europol, and a private cybersecurity firm. That’s not a cleanup. That’s a handover. The question isn’t whether Sality is gone. The question is whose hands the controls passed into.
Follow the Contractors
CrowdStrike doesn’t participate in takedowns out of civic duty. They participate because the data is the prize. Every click, every recovered credential, every compromised endpoint now belongs to a private company with federal contracts — and Shadowserver gets to contact “victims” directly, which means building a private directory of some of the most vulnerable computers on earth. The visible story is that a Russian botnet is dead. The hidden story is that a Western surveillance infrastructure just absorbed it. Who benefits from keeping malware alive just long enough to harvest it? Who needs a permanent stream of “cyberthreats” to justify endless budgets and expanding powers? You don’t have to believe me. Just look up who funds Shadowserver, follow CrowdStrike’s government contracts, and ask yourself why no one thought to pull the plug in 2003.


