Wednesday, 02 September 2026 · Europe
EUR/USD 1.159 EUR/GBP 0.8566 EUR/CHF 0.9394 EUR/PLN 4.331 All rates →
Sign in · Join
EUROPES The European Report
European Edition Wednesday, 02 September 2026
LATEST Will Hamilton, Russell or Norris seize title-race opening at Monza? Le Flash →
Tech & Startups

CrowdStrike and the FBI are dismantling Sality after 23 years

CrowdStrike and the FBI are dismantling Sality after 23 years

Sality has been infecting computers since 2003, making it older than the iPhone, Facebook, and much of the security industry now working to dismantle it. US law enforcement and CrowdStrike began taking it apart this week, Reuters reported. For more than two decades, the operation has been used for fairly ordinary cybercrime. Infected machines have […] This story continues at The Next Web

Sality has been infecting computers since 2003, making it older than the iPhone, Facebook, and much of the security industry now working to dismantle it. US law enforcement and CrowdStrike began taking it apart this week, Reuters reported .

For more than two decades, the operation has been used for fairly ordinary cybercrime. Infected machines have been used to send spam, launch distributed denial-of-service attacks and steal cryptocurrency, with the criminals shifting between them as different opportunities became profitable.

The way authorities took it down is more unusual. CrowdStrike reverse-engineered the botnet, identified weaknesses in its structure, and then seeded it with false information that convinced infected machines to disconnect from their controller.

“This was the most complex botnet takeover we have ever done,” said Tillmann Werner, a CrowdStrike researcher. The company announced the operation at its Day Zero threat intelligence summit in Las Vegas.

Sality managed to survive for so long partly because of how it was designed. It spread by infecting executable files rather than depending on a single command server, while its peer-to-peer structure meant there was no central machine that could simply be taken offline to bring down the rest.

US authorities handled the legal side of the operation. The FBI and Justice Department seized the web domains used to control infected machines, removing part of the infrastructure while CrowdStrike worked to break the remaining connections.

“Cybercriminals, botnets, and malware are a clear and present danger,” said Bill Essayli, first assistant United States attorney. David Watson of the Shadowserver Foundation described Sality as a way into a large number of organisations.

That helps explain why a 23-year-old botnet is still worth dismantling. Sality’s value was not necessarily what it could do itself, but the access it provided to compromised networks, which could then be sold or used for other attacks.

The problem is not limited to the countries named in the announcement. Old infections remain a risk in Europe too, where industrial systems, small business servers and public sector machines can still be running software old enough to be vulnerable to malware written in 2003.

The longevity of an infection says as much about the victims as it does about the attackers. Machines can remain compromised for years because nobody notices, nobody patches them, or the software continues running on systems that their owners rarely think about anymore.

Takedowns like this do not necessarily lead to arrests, and none have been announced in this case. When the operators are outside the reach of the courts carrying out the action, seizing infrastructure and cutting off connections are among the few options available.

Private security companies taking a more active role is also becoming increasingly common. The US has now authorised private companies to run cyber operations abroad , and CrowdStrike’s use of false data inside a criminal network sits close to that evolving boundary between cybersecurity and offensive operations.

There is no guarantee the takedown will be permanent. Botnets have been dismantled and rebuilt before, and the computers being disconnected today still contain whatever vulnerability allowed Sality to get onto them in the first place.

The false-data technique is particularly interesting because it could have wider applications. A distributed network does not necessarily have to be broken through encryption or brute force if its nodes can be persuaded that the controller they trust is no longer available.

Neither the number of infected machines nor the losses linked to the operation has been disclosed. After more than two decades, both would give a better sense of just how large Sality became.

The takedown also comes as AI-driven cyber threats are dominating the conversation, from the FSB’s warning to G20 finance ministers to OpenAI’s account of what its latest models can find. Sality is a reminder that the older problems have not disappeared just because the newer ones are getting more attention.

A botnet does not have to be particularly sophisticated to survive for 23 years. It just has to stay unnoticed, which is still surprisingly easy.

More from Tech & Startups