International Authorities Disrupt Sality Botnet Targeting Cryptocurrency
- On Aug. 31, authorities from the U.S., Bulgaria, Hungary, and Romania disrupted the Sality P2P botnet.
- Sality was associated with over 11 million unique IP addresses and could control up to 1 million infected devices simultaneously.
- The botnet’s EggJagger component reportedly stole at least $150,000 in cryptocurrency.
- Law enforcement seized domains linked to Sality and conducted a sinkhole operation to isolate infected devices.
- Sality has been active since 2003, evolving into a decentralized network that facilitated various cyberattacks.
The disruption of the Sality botnet highlights significant international cooperation in combating cybercrime targeting cryptocurrency platforms. With total damages from such incidents reaching $3.63 billion since early 2025, this operation is crucial for enhancing cybersecurity.
The successful takedown of Sality underscores its extensive reach, having operated across millions of IP addresses while stealing substantial amounts of cryptocurrency through its malicious components like EggJagger.