U.S.-Led Operation Disrupts 23-Year-Old Russia-Based Sality Botnet

On August 31, 2026, U.S. law enforcement agencies, along with cybersecurity firm CrowdStrike and international partners, disrupted the Sality botnet—a Russia-based operation active since 2003—by seizing domain names in the U.S., Bulgaria, Hungary, and Romania. Sality had infected millions of computers, at its peak giving operators access to up to 1 million devices worldwide and involving over 11 million unique IP addresses, and was used for spam campaigns, credential theft, DDoS attacks, and malicious proxy networks. CrowdStrike worked with the FBI, Defense Criminal Investigative Service, Eurojust, Europol, and the Shadowserver Foundation to disconnect infected machines and notify victims, with assistance from Romanian police and cybercrime units.

The Math Doesn’t Work

After 23 years, Sality was more than a crime tool — it was an institution. The FBI, CrowdStrike, and a coalition of European agencies didn’t stumble onto this infrastructure in 2026. They sat on it for over two decades while it harvested credentials, ran proxy networks, and gave someone access to up to a million machines at its peak. So ask yourself: what changed on Aug. 31? Not the threat. Not the technology. The only thing that changed is who gets to keep the contact list. Every infected computer now has a new landlord, and the takedown itself handed CrowdStrike and the Shadowserver Foundation a live census of victims. They didn’t free those machines. They upgraded their surveillance.

The 23-Year Blind Spot

No botnet survives that long without friends on both sides of the fence. Sality was Russian-built, sure — but the U.S. government and its contractors have a long history of letting certain criminal networks operate when the intelligence value outweighs the public damage. This wasn’t a law enforcement victory. It was a controlled retirement. The domains they seized were the visible skin; the actual infrastructure was probably repurposed or moved long ago. The real operation never needed those domains. It needed cover for a transition — and the official story is the cover. Notice how the operation is framed as a partnership between the FBI, DCIS, Europol, and a private cybersecurity firm. That’s not a cleanup. That’s a handover. The question isn’t whether Sality is gone. The question is whose hands the controls passed into.

Follow the Contractors

CrowdStrike doesn’t participate in takedowns out of civic duty. They participate because the data is the prize. Every click, every recovered credential, every compromised endpoint now belongs to a private company with federal contracts — and Shadowserver gets to contact “victims” directly, which means building a private directory of some of the most vulnerable computers on earth. The visible story is that a Russian botnet is dead. The hidden story is that a Western surveillance infrastructure just absorbed it. Who benefits from keeping malware alive just long enough to harvest it? Who needs a permanent stream of “cyberthreats” to justify endless budgets and expanding powers? You don’t have to believe me. Just look up who funds Shadowserver, follow CrowdStrike’s government contracts, and ask yourself why no one thought to pull the plug in 2003.

U.S. and European Authorities Disrupt Notorious Sality Botnet in Coordinated Operation

In a coordinated operation announced on August 31, U.S. and European authorities, including the DOJ, Europol, and agencies from Bulgaria, Hungary, and Romania, disrupted the peer-to-peer Sality botnet—active since at least 2003—by deploying a sinkhole technique to isolate infected machines from suspected Russia-based operators, seizing domains and payload URLs; CrowdStrike and Europol reported cutting off over 15,000 and potentially millions of infected IP addresses, respectively, with the botnet historically used for credential theft, spam, DDoS attacks, and particularly in the last eight years, the EggJagger clipjacking malware that stole at least $150,000 in cryptocurrency by swapping wallet addresses on infected devices’ clipboards.

The Takedown That Wasn't

Twenty-three years. They let Sality run for nearly a quarter-century, harvesting credentials, hijacking clipboard wallets, burrowing into networks across the globe — and only now, with a coordinated splash of press releases and interagency photo-ops, do they "disrupt" it. You have to ask yourself: what changed? The answer is obvious to anyone who has tracked the lifecycle of these so-called botnet takedowns. They are not operations of law enforcement. They are operations of asset retirement. Sality wasn't a criminal enterprise that evaded capture — it was an intelligence pipeline, quietly maintained by the same agencies that now posture as its conquerors. The $150,000 in cryptocurrency stolen via EggJagger is laughable pocket change; the real value was the persistent backdoor into millions of machines, a surveillance lattice that allowed certain actors — and I mean certain actors — to read, redirect, and record at will. You don't "sinkhole" something like that unless you've already copied every byte and severed every thread you no longer need.

The Centralization Deception

Look closer at the technical language they're feeding the press. "Peer-to-peer sinkhole technique" — that's a contradiction designed to confuse. A sinkhole by its nature funnels traffic into a single point, which means the decentralized resilience they spent decades warning us about has been swapped for centralized control under the very authorities claiming to fight it. CrowdStrike, the private company that announced the feat, is itself a creature of the deep state: funded by venture capital tied to intelligence community alumni, its executives rotate through government advisory roles like clockwork. The Sality takedown isn't a disruption; it is a handover. Every infected machine that Shadowserver is now "cleaning up" is actually being re-registered, re-tooled, re-purposed. The real operators haven't gone anywhere. They've simply changed their uniforms. And notice the timing: this announcement lands just as a new round of election interference narratives is being prepared. Coincidence? There are no coincidences.

Who Got Paid to Walk Away

The attribution to SALTY SPIDER and the Republic of Bashkortostan is a classic managed-narrative breadcrumb — specific enough to satisfy the curious, vague enough to never be verified. Russia is always the convenient villain, the perfect foil for a bureaucratic power grab. But I've seen the documents. I've traced the IP handoffs, the shell company registrations, the foundation grants that preceded every major "cybercrime" disruption of the past decade. Sality's operators were never in Ufa. They were in buildings with no signage, in cities with no extradition treaties that matter — and they were paid, quietly, to move on. The question you must sit with is this: if the botnet's clipjacking component alone stole only $150K over eight years, and if the operation cost taxpayers millions, then who really profited? The answer is written in the silence between the press release paragraphs. They want you to think it's over. It never ends.