Loading market data...

Sality Botnet Dismantled After Eight Years, DOJ and CrowdStrike Isolate 15,000 Machines

Sality Botnet Dismantled After Eight Years, DOJ and CrowdStrike Isolate 15,000 Machines

The Sality botnet, a sprawling malware network that spent eight years stealing Bitcoin and Ethereum, has been dismantled. The U.S. Department of Justice and cybersecurity firm CrowdStrike worked together on the takedown, isolating more than 15,000 infected machines across four countries.

Eight years of theft

Sality first appeared in 2018, and for the better part of a decade it quietly infected computers and used them to mine and swipe cryptocurrency. The botnet's operators didn't just hijack processing power — they targeted wallets and exchange credentials, making off with Bitcoin and Ethereum before victims knew what hit them.

The takedown didn't happen overnight. Investigators spent months mapping the infrastructure, tracking command-and-control servers, and coordinating with law enforcement in multiple jurisdictions. When they finally pulled the plug, the operation spanned four countries, though the DOJ didn't name them in the initial announcement.

How the takedown worked

CrowdStrike's threat intelligence team identified the botnet's command nodes and worked with the DOJ to seize them. That cut off the operators' ability to send instructions to infected machines. In a separate step, the two organizations isolated more than 15,000 compromised systems, preventing them from being repurposed or sold off to other criminals.

The isolation is a key detail. Simply shutting down the servers wouldn't have cleaned the infected machines — they'd still be sitting there, vulnerable to a new operator. By isolating them, the takedown effectively neutralized the network's reach.

What this means for crypto users

For anyone who held crypto on a compromised machine, the news is a reminder that botnets don't just mine coins — they steal them. Sality was particularly good at grabbing wallet files and clipboard data, swapping out addresses during transactions.

The DOJ and CrowdStrike haven't said whether they recovered any of the stolen funds. That's often the hardest part of a takedown; the assets are long gone by the time the infrastructure is seized.

What's clear is that the botnet is down, and the 15,000 machines it controlled are no longer part of a criminal network. Whether the operators face charges is another question — the DOJ didn't announce any arrests, and it's possible the people behind Sality are still at large.