<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/crowdstrike-and-the-fbi-are-dismantling-sality-after-23-years-p9d5vgu8i" -->

---
title: CrowdStrike and the FBI are dismantling Sality after 23...
description: US law enforcement and CrowdStrike are dismantling Sality, a peer-to-peer botnet that has infected machines since 2003 and was used for spam, DDoS attacks and...
canonical: https://daily.dev/posts/crowdstrike-and-the-fbi-are-dismantling-sality-after-23-years-p9d5vgu8i
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: CrowdStrike and the FBI are dismantling Sality after 23 years | daily.dev
og:description: US law enforcement and CrowdStrike are dismantling Sality, a peer-to-peer botnet that has infected machines since 2003 and was used for spam, DDoS attacks and...
og:url: https://daily.dev/posts/crowdstrike-and-the-fbi-are-dismantling-sality-after-23-years-p9d5vgu8i
og:image: https://api.daily.dev/og/posts/p9D5vgU8I.png
og:image:alt: CrowdStrike and the FBI are dismantling Sality after 23 years
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# CrowdStrike and the FBI are dismantling Sality after 23 years

**[The Next Web](https://daily.dev/sources/tnw)** · 4 min read · 0 upvotes · 0 comments

## Summary

US law enforcement and CrowdStrike are dismantling Sality, a peer-to-peer botnet that has infected machines since 2003 and was used for spam, DDoS attacks and cryptocurrency theft. CrowdStrike reverse-engineered the botnet and seeded it with false data to convince infected machines to disconnect from their controllers, while the FBI and Justice Department seized associated web domains. CrowdStrike researcher Tillmann Werner called it the most complex botnet takeover the company has performed. No arrests have been announced, and the scale of infections or financial losses remains undisclosed. The takedown highlights old, unpatched infections still lurking on industrial and public sector systems, and signals growing private-sector involvement in offensive cyber operations.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://thenextweb.com/news/crowdstrike-and-the-fbi-are-dismantling-sality-after-23-years>

## Questions this post answers

### How did CrowdStrike and the FBI take down the Sality botnet?

CrowdStrike reverse-engineered the Sality botnet, identified structural weaknesses, and seeded it with false information that convinced infected machines to disconnect from their controllers. Simultaneously, the FBI and Justice Department seized the web domains used to control infected machines. CrowdStrike researcher Tillmann Werner called it the most complex botnet takeover the company has performed, announced at its Day Zero threat intelligence summit in Las Vegas.

_Security teams tracking botnet takedown techniques can follow evolving cases like this on daily.dev._

### Why was the Sality botnet able to survive for 23 years?

Sality survived since 2003 because it spread by infecting executable files rather than relying on a single command server, and its peer-to-peer structure meant no central machine could be taken offline to disable the rest. Infections persisted on unpatched industrial systems, small business servers, and public sector machines whose owners rarely noticed or maintained them.

_Anyone hardening infrastructure against long-lived malware can track findings like these on daily.dev._

### What was the Sality botnet used for?

Sality-infected machines were used for ordinary cybercrime including sending spam, launching distributed denial-of-service attacks, and stealing cryptocurrency, with operators shifting between activities as opportunities became profitable. Its real value was the access it gave to compromised networks, which could be sold or reused for further attacks, according to the Shadowserver Foundation's David Watson.

_Teams assessing botnet-driven risk to their networks can follow ongoing coverage on daily.dev._

---

Tags: [#malware](https://daily.dev/tags/malware)

[View this post on daily.dev](https://daily.dev/posts/crowdstrike-and-the-fbi-are-dismantling-sality-after-23-years-p9d5vgu8i)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"CrowdStrike and the FBI are dismantling Sality after 23 years","url":"https://daily.dev/posts/crowdstrike-and-the-fbi-are-dismantling-sality-after-23-years-p9d5vgu8i","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/crowdstrike-and-the-fbi-are-dismantling-sality-after-23-years-p9d5vgu8i"},"datePublished":"2026-09-02T10:32:03.932Z","dateModified":"2026-09-03T11:24:41.842Z","description":"US law enforcement and CrowdStrike are dismantling Sality, a peer-to-peer botnet that has infected machines since 2003 and was used for spam, DDoS attacks and...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/60f31f8b00ca6c4439396a620024ff95?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/60f31f8b00ca6c4439396a620024ff95?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"The Next Web","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"The Next Web","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/tnw","url":"https://daily.dev/sources/tnw"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/crowdstrike-and-the-fbi-are-dismantling-sality-after-23-years-p9d5vgu8i","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"malware","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"The Next Web","item":"https://daily.dev/sources/tnw"},{"@type":"ListItem","position":3,"name":"CrowdStrike and the FBI are dismantling Sality after 23 years"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/crowdstrike-and-the-fbi-are-dismantling-sality-after-23-years-p9d5vgu8i#faq","mainEntity":[{"@type":"Question","name":"How did CrowdStrike and the FBI take down the Sality botnet?","acceptedAnswer":{"@type":"Answer","text":"CrowdStrike reverse-engineered the Sality botnet, identified structural weaknesses, and seeded it with false information that convinced infected machines to disconnect from their controllers. Simultaneously, the FBI and Justice Department seized the web domains used to control infected machines. CrowdStrike researcher Tillmann Werner called it the most complex botnet takeover the company has performed, announced at its Day Zero threat intelligence summit in Las Vegas. Security teams tracking botnet takedown techniques can follow evolving cases like this on daily.dev."}},{"@type":"Question","name":"Why was the Sality botnet able to survive for 23 years?","acceptedAnswer":{"@type":"Answer","text":"Sality survived since 2003 because it spread by infecting executable files rather than relying on a single command server, and its peer-to-peer structure meant no central machine could be taken offline to disable the rest. Infections persisted on unpatched industrial systems, small business servers, and public sector machines whose owners rarely noticed or maintained them. Anyone hardening infrastructure against long-lived malware can track findings like these on daily.dev."}},{"@type":"Question","name":"What was the Sality botnet used for?","acceptedAnswer":{"@type":"Answer","text":"Sality-infected machines were used for ordinary cybercrime including sending spam, launching distributed denial-of-service attacks, and stealing cryptocurrency, with operators shifting between activities as opportunities became profitable. Its real value was the access it gave to compromised networks, which could be sold or reused for further attacks, according to the Shadowserver Foundation's David Watson. Teams assessing botnet-driven risk to their networks can follow ongoing coverage on daily.dev."}}]}
```

