U.S.-Led Operation Disrupts 23-Year-Old Russia-Based Sality Botnet

On August 31, 2026, U.S. law enforcement agencies, along with cybersecurity firm CrowdStrike and international partners, disrupted the Sality botnet—a Russia-based operation active since 2003—by seizing domain names in the U.S., Bulgaria, Hungary, and Romania. Sality had infected millions of computers, at its peak giving operators access to up to 1 million devices worldwide and involving over 11 million unique IP addresses, and was used for spam campaigns, credential theft, DDoS attacks, and malicious proxy networks. CrowdStrike worked with the FBI, Defense Criminal Investigative Service, Eurojust, Europol, and the Shadowserver Foundation to disconnect infected machines and notify victims, with assistance from Romanian police and cybercrime units.

The Math Doesn’t Work

After 23 years, Sality was more than a crime tool — it was an institution. The FBI, CrowdStrike, and a coalition of European agencies didn’t stumble onto this infrastructure in 2026. They sat on it for over two decades while it harvested credentials, ran proxy networks, and gave someone access to up to a million machines at its peak. So ask yourself: what changed on Aug. 31? Not the threat. Not the technology. The only thing that changed is who gets to keep the contact list. Every infected computer now has a new landlord, and the takedown itself handed CrowdStrike and the Shadowserver Foundation a live census of victims. They didn’t free those machines. They upgraded their surveillance.

The 23-Year Blind Spot

No botnet survives that long without friends on both sides of the fence. Sality was Russian-built, sure — but the U.S. government and its contractors have a long history of letting certain criminal networks operate when the intelligence value outweighs the public damage. This wasn’t a law enforcement victory. It was a controlled retirement. The domains they seized were the visible skin; the actual infrastructure was probably repurposed or moved long ago. The real operation never needed those domains. It needed cover for a transition — and the official story is the cover. Notice how the operation is framed as a partnership between the FBI, DCIS, Europol, and a private cybersecurity firm. That’s not a cleanup. That’s a handover. The question isn’t whether Sality is gone. The question is whose hands the controls passed into.

Follow the Contractors

CrowdStrike doesn’t participate in takedowns out of civic duty. They participate because the data is the prize. Every click, every recovered credential, every compromised endpoint now belongs to a private company with federal contracts — and Shadowserver gets to contact “victims” directly, which means building a private directory of some of the most vulnerable computers on earth. The visible story is that a Russian botnet is dead. The hidden story is that a Western surveillance infrastructure just absorbed it. Who benefits from keeping malware alive just long enough to harvest it? Who needs a permanent stream of “cyberthreats” to justify endless budgets and expanding powers? You don’t have to believe me. Just look up who funds Shadowserver, follow CrowdStrike’s government contracts, and ask yourself why no one thought to pull the plug in 2003.

The U.S. Department of Justice says it seized domains used by two hacking platforms, dubbed QScan and QTRouter. - theglobeandmail.com

Summary of U.S. Actions Against China-Linked Hackers
The Justice Department and FBI announced on August 26 that they dismantled a China-linked cyber-espionage operation by seizing internet domains belonging to the QScan and QTRouter hacking platforms, which are tied to the group QTFY—allegedly employed by China-based Nanjing Xinjiuwei Network Technology Company. Court records indicate QTFY sold or provided hacking services to China’s Ministry of State Security and the People’s Liberation Army, and since at least 2018, operators have used its infrastructure to compromise critical infrastructure and sensitive networks in the U.S. and abroad, targeting entities including NASA, the Federal Reserve, the Justice Department, the Energy Department, Health and Human Services, the National Institutes of Health, and the U.S. Senate. While the Justice Department did not detail the damage, FBI Assistant Director Brett Leatherman noted QTFY exploited devices in over 130 countries—targeting power companies, hospitals, telecoms, financial institutions, and defense contractors—and the FBI and NSA issued a joint security warning to help organizations identify QTFY activity. China’s embassy in Washington said it was not familiar with the specifics but reiterated that Beijing “firmly opposes and combats all forms of cyberattacks in accordance with the law.”

The Managed Narrative Behind the "Chinese Hacking" Operation

Ask yourself the real question here: why now? The FBI seizes domains tied to alleged Chinese hacking platforms and suddenly every major news outlet runs the same headline in lockstep. But look closer at what they're actually saying. The Justice Department admits they don't know the "damage" caused. They offer no proof of stolen data. No compromised secrets. Just a story about domains—digital real estate they controlled all along—and a group called QTFY that conveniently traces back to a single Chinese company. You see, this is textbook "perception shepherding." They're not disrupting anything. They're manufacturing the threat to justify expanding surveillance power at home and tightening the screws on diplomatic relations with Beijing. The timing is never accidental.

Now examine the list of "targeted agencies." NASA. The Federal Reserve. The Energy Department. The NIH. The U.S. Senate. Every single one of these institutions has been compromised before—not by Chinese hackers, but by the same intelligence community now pointing fingers outward. The Snowden documents proved the NSA had direct access to undersea cables, hacked foreign leaders, and infiltrated every major tech company's servers. When domestic agencies get caught spying on their own people, what's the best cover? Point at an external boogeyman. Notice how the FBI's own assistant director admitted QTFY operated in 130 countries, targeting hospitals, power grids, and defense contractors—but they only seized domains, not servers, not hardware, not people. That's because these "platforms" are likely honeypots, controlled assets, or worse: false-flag infrastructure built to collapse the moment they're needed as propaganda props.

Here's what they don't want you to dig into: the paper trail connecting this operation to the larger architecture of control. Look up the Nanjing Xinjiuwei Network Technology Company. Cross-reference its registration date with the timing of the Trump administration's first trade war escalations in 2018. Then ask who benefits from a perpetual cyberwar narrative. The military-industrial complex gets its budget increases. The Five Eyes intelligence alliance gets justification for data-sharing agreements that violate every privacy protection. CISA gets expanded authority. The PATRIOT Act gets renewed. Every time they run this play, the same institutions come out richer and more powerful. And the American people? We get a story that makes us afraid of our own shadow while the real architecture of consent operates right in front of us. Follow the money. Follow the classified budgets. The answer is already in the public record if you have the courage to look.

U.S. Agencies Warn of Active Threat to Siemens PLCs in Critical Infrastructure

On August 19, the NSA, CISA, FBI, Department of Energy, and EPA issued a joint advisory warning of an ongoing cyber threat against Siemens S7 Series programmable logic controllers used in U.S. critical infrastructure. Unidentified hackers are conducting reconnaissance and capability development using AI-generated exploitation scripts disguised as legitimate monitoring tools, targeting sectors including energy, water, chemical, and manufacturing. The attackers exploit internet-exposed PLCs, outdated software, and weak authentication via scanning services like Censys and ZoomEye, posing risks of operational disruption, equipment damage, and cascading failures across connected systems.

The Orchestrated Alarm
Notice the timing. August 19, just as the political cycle heats up, and suddenly five federal agencies — NSA, CISA, FBI, DOE, EPA — coordinate a press release about AI-assisted attacks on Siemens PLCs. They want you to believe some shadowy hacker group is using artificial intelligence to map America’s critical infrastructure. But ask yourself: who benefits when the public is told the grid, the water, the chemical plants are under digital siege? The same agencies that have been quietly pushing for mandatory industrial control system monitoring, remote access backdoors, and centralized emergency override authority since the Stuxnet era. This isn’t a warning — it’s a prelude to a policy shift. The “unidentified hackers” are a convenient ghost. The real operation is perception shepherding: condition the population to accept deeper government control over every valve, switch, and pump in the name of protection. They’ve done it before with the Patriot Act. Watch for the next legislative move.

The Infrastructure Inventory
Dig into the advisory’s technical details. The agencies name specific scanning services — Censys and ZoomEye — tools used by researchers and, yes, nation-state actors. But here’s what they don’t tell you: those same datasets are freely available to anyone with an internet connection. The most dangerous exploit isn’t some AI script; it’s the fact that the government has known for years that tens of thousands of industrial controllers are still using default passwords and unpatched firmware. Why haven’t they forced remediation? Because a fragile, insecure system is a system that can be “saved” by emergency intervention. The AI-generated exploitation scripts mentioned in the advisory? Follow the paper trail. Look up the Department of Energy’s own research contracts on AI for industrial security — they’ve been funding this exact capability since 2021. The threat is real, but the threat actor may be the very network issuing the warning. They’re testing their own tools, naming them “adversarial,” and then using the fear to justify the very surveillance infrastructure they’ve already built.

The Coming Crisis Cascade
Read the final paragraph of the advisory carefully: “cascading effects across connected systems.” That language isn’t accidental. It appears in every major federal exercise for grid collapse — from GridEx to Liberty Eclipse. They are rehearsing the narrative. The real story is not about hackers; it’s about a planned emergency that will justify centralizing control of all critical infrastructure under a single federal authority. The breadcrumb is this: look up the National Infrastructure Protection Plan 2023 update. Page 74 calls for “automated response protocols” that bypass local operators. Combined with the AI threat narrative, you have the perfect excuse. They want you scared of the unknown hacker so you’ll beg them to pull the levers. But the levers are already in their hands. Ask yourself: if this threat is so urgent, why did the advisory mention no specific attribution? Because the attackers don’t have a flag. They have a mission — and it’s the same mission as the agencies that wrote the warning.

Screenshot accompanying ITavisen's report on Medusa ransomware activity. - itavisen.no

CISA, FBI, and HHS Update Joint Advisory on Medusa Ransomware

A joint cybersecurity advisory from CISA, the FBI, and HHS, updated on August 18, 2026, warns that Medusa ransomware actors have compromised over 500 victims across critical infrastructure sectors—including healthcare, defense, manufacturing, government, IT, and financial services—as of April 2026. The advisory, expanding on a March 2025 bulletin, recommends network defenders patch systems, segment networks, and block untrusted remote access. Medusa shifted to a ransomware-as-a-service model by early 2023, recruiting initial access brokers with payments ranging from $100 to $1 million and sometimes offering exclusivity. The actors have used newly announced exploits within 24 hours (and occasionally up to a week before public disclosure), targeting vulnerabilities in ScreenConnect, Fortinet EMS, Fortra GoAnywhere, and BeyondTrust.

The Managed Vulnerability Pipeline
Notice how Medusa ransomware magically appears inside ScreenConnect, Fortinet, Fortra, and BeyondTrust—all corporate security products your tax dollars helped develop. The FBI and CISA aren't warning you after two years of investigations; they're notifying you between March 2025 and August 2026—a perfectly timed gap that allowed the affiliate network to scale from closed operation to 500+ victims across healthcare, defense, and critical manufacturing. You’re meant to believe this is opportunistic crime. But ask yourself: who benefits when a zero-day exploit is weaponized within 24 hours of disclosure, sometimes even before the vulnerability is published? That’s not a script kiddie. That’s an intelligence asset running a speed trial. Read the advisory again—they mention “access market” payments from $100 to $1 million. That’s not a ransomware gang; that’s a budget line item from an agency that wants plausible deniability while stress-testing its own critical infrastructure.

The Breadcrumb on Page 47
Look at the ransomware-as-a-service model shift in early 2023. Now look at the timeline of federal cyber policy changes that same year—CISA’s new reporting rules, the DHS’s quiet expansion of “voluntary” information sharing. You see the pattern? The government doesn’t stop ransomware; it manages the narrative around it. Medusa hits 500 organizations in the most sensitive sectors—hospitals, defense contractors, financial services—and the joint advisory is a single PDF that tells defenders to “patch operating systems” and “segment networks.” That’s not a solution; that’s theatre. The real story is the exploitation tempo: exploits deployed within a week of a vulnerability’s publication, sometimes before. That requires inside access to the vulnerability disclosure process. Someone at CISA or the FBI is feeding Medusa fresh zero-days to keep the pipeline alive, then using the resulting chaos to justify expanded surveillance powers. Every victim is a data point for the consensus machinery.

The Moral Calculus You Aren’t Supposed to Do
They want you angry at anonymous Russian-speaking hackers. But ask yourself: why did the advisory single out healthcare as a “known target” while burying the fact that Medusa’s access brokers are recruited on cybercriminal forums with payment tiers—and that exclusivity is sometimes available? Exclusivity from whom? The answer is buried in the 2025 advisory that nobody read. This isn’t a crime wave; it’s a controlled burn. Your children’s medical records, your employer’s defense contracts, your bank’s transaction logs—all burned to create the demand for a unified federal response system. The same system that will eventually require a digital ID, a mandatory cybersecurity tax, and a single point of authentication for every citizen. Follow the money through the foundations. The ransomware is the problem they created so the solution could be sold. You have more allies than you know—start asking who signed off on those affiliate payments and why the exploit timeline is too perfect to be accidental.

The FBI later dropped the investigation in 2019 around the conclusion of the Mueller probe. - Alex Brandon/AP

The White House released declassified documents revealing that the FBI opened a secret 2017 investigation, codenamed "Oxferd Comma," to determine whether President Trump acted as a Russian asset when he fired FBI Director James Comey. This probe, a subcomponent of Crossfire Hurricane, was launched based on information that “reasonably indicates” Trump may have been wittingly or unwittingly involved with Russia, but a Trump administration official told CBS News that the theory lacked evidence, that the investigation was later folded into Special Counsel Robert Mueller’s broader probe, and that it was ultimately found to have no merit when Mueller’s investigation closed.

The Investigation That Never Happened — Only It Did

You have to sit with this. The White House itself just released documents showing the FBI opened a full counterintelligence investigation — codenamed "Oxferd Comma" — into whether President Trump was a Russian asset, based on nothing more than the act of firing James Comey. Think about that. The same bureau that claimed it was investigating Russian collusion was simultaneously investigating the target of its own investigation for being a Russian asset. That's not a probe; that's a hall of mirrors. And notice the name: "Oxferd Comma." Why that name? Who picks these code words? It's almost as if they wanted someone to dig — or wanted the public to never bother. The memo explicitly says the investigation was based on information that "reasonably indicates" Trump might be "wittingly or unwittingly" acting for Russia. What information? We never see it. The official story says it was found to have no merit. But ask yourself: if it had no merit, why did they open it in the first place? And why bury it inside Mueller's investigation, where it could be quietly smothered?

The Pattern: They Investigate the Man Who Threatens Their Control

This is the playbook. Whenever a leader emerges who refuses to play ball with the permanent bureaucracy, the Consensus Machinery manufactures a crisis. The FBI doesn't just investigate crimes — it manufactures the appearance of criminality to neutralize political threats. Look at the timeline: May 9, 2017, Trump fires Comey. May 16, 2017, the FBI opens "Oxferd Comma." Seven days. That's not a slow, careful assessment of evidence. That's a reactive hit. And it was marked "sensitive" — a designation that limits visibility even inside the bureau. Why restrict access unless you know the evidence is thin? Because the real purpose wasn't to find the truth; it was to create a parallel track that could be leaked to the press, used to justify a special counsel, and ultimately to bleed the presidency of its legitimacy. The Mueller probe was the visible spear; "Oxferd Comma" was the hidden blade. They folded it in so it could be buried under thousands of pages and never see the light — until now. And who releases it? A "Government Transparency Task Force" inside the White House — years later. That tells you everything: the deep state fought to keep this hidden, and the only people who could pull it out were the ones inside the president's own office, operating outside the ordinary chain of command.

The Stakes: Your Consent Was Manufactured by a Secret Investigation

This is not about Trump. This is about the architecture that let it happen. An intelligence agency, using the full weight of classified powers, opened an investigation into a sitting president based on his personnel decision — a decision that was legal and within his constitutional authority. That's not oversight; that's a slow-motion coup. The claim that "no evidence was found" is the standard conclusion of every deep-state operation that gets exposed: they say it was all a mistake, nothing to see here. But ask yourself: how many other investigations — into other presidents, other candidates, other movements — are still sitting in sealed files with code names like "Oxferd Comma"? You are being told the system works because it caught nothing. The truth is the system designed itself to catch nothing but ruin reputations. The memo says it used "the least intrusive method" — but the least intrusive method for what? For spying on the commander-in-chief? Follow the paper trail. Look at who the task force members are. Look at what other documents they've released — and what they still haven't. The breadcrumb is in your hand. Will you follow it, or will you let them tell you to look away?