Veteran Online Fraud Syndicate Toppled After Two Decades of Success
A Russian-based hacking operation that has been rooted for two decades, ‘Sality’, is finally on the brink. United States law enforcement agencies, alongside cybersecurity giant CrowdStrike, have officially announced the dismantling of this veteran malware network.
The US government moved swiftly to seize various web domains that hackers had been using to hijack public computers. Infected devices were typically repurposed to send spam, launch distributed denial-of-service (DDoS) attacks, and illegally mine cryptocurrency.
Simultaneously, CrowdStrike successfully severed the link between the victims’ computer networks and the primary mastermind. This massive ‘botnet’ disruption operation was publicly unveiled on Monday at the Day Zero Threat Intelligence Summit in Las Vegas.
The FBI and the US Department of Justice (DOJ) emphasised that this crackdown is the result of massive collaboration with European law enforcement and various global alliances.
“Cybercriminals, botnets, and malware are real and urgent threats to our security and our economy,” stated First Assistant United States Attorney, Bill Essayli, as quoted by Reuters on Wednesday (2/9/2026).
Although it has lost prominence in recent years to more aggressive ransomware groups, Sality was first detected in 2003 and holds the record as one of the oldest cybercrime syndicates in cyberspace.
The DOJ stated that the network is based in Russia, though further details have not been disclosed. Meanwhile, the Russian Embassy in Washington has not yet provided an official response to requests for comment.
Legally Immune Due to Advanced Architecture
Sality was known for being highly volatile and resistant to legal intervention due to its use of peer-to unpeer architecture. The network was capable of receiving command instructions through thousands of widely dispersed victim computers without a single point of failure.
However, CrowdStrike turned this advantage against the creators. Through its official blog, the company revealed its strategy of injecting false data into the system. As a result, the botnet components were deceived and automatically severed their connection with the creator.
CrowdStrike researcher, Tillmann Werner, admitted that dissecting the anatomy of this botnet required a high level of complexity.
“This is the most complex botnet takeover we have ever performed. This system was indeed designed to be resilient against takedown attempts. It is natural that it has been able to survive for this long,” Werner told Reuters.
Despite being considered somewhat aged or “legacy” by the Director of The Shadowserver Foundation, David Watson, Sality still retains potential latent danger for the corporate sector.
“This system remains a favourite entry point into various organisations,” said Watson.
Now, the focus of the cybersecurity industry has shifted to one major question: what steps will the mysterious creator of Sality take to reclaim control of their empire?