Long-Running Sality Botnet Finally Taken Down After Eight-Year Crypto Theft Campaign
CrowdStrike and the U.S. Department of Justice have successfully dismantled the Sality botnet, a malware network that operated for eight years while stealing cryptocurrency from infected machines. The takedown isolated more than 15,000 compromised computers across four countries, cutting off the attackers' ability to control the infected devices.
Botnets like Sality work by silently infecting computers and networking them together under the control of criminals, who can then use the combined computing power for various malicious purposes, including cryptocurrency theft. The long lifespan of this operation highlights how such threats can persist for years before being detected and dismantled, often causing ongoing financial harm to victims who may be unaware their systems are compromised.
While this takedown removes a significant threat, businesses should remain vigilant, as botnet operators often attempt to rebuild their infrastructure or new criminal groups adopt similar tactics. Regular security monitoring and prompt patching remain essential defences against these persistent threats.