Industry News

Long-Running Sality Botnet Dismantled After Years of Crypto Theft

Cointribune · 3 Sept 2026
Key Takeaway If your business handles cryptocurrency, ensure all systems are patched, run reputable endpoint security, and regularly check for signs of unusual or unauthorised activity.

The Sality botnet, first identified back in 2003, has reportedly been dismantled following a lengthy operation targeting cryptocurrency users. For the past eight years, the network of infected machines was used to steal Bitcoin and Ethereum from victims, adding a lucrative financial motive to a piece of malware that has plagued computers for over two decades.

Botnets like Sality work by quietly infecting large numbers of computers, often without the owner's knowledge, and using that collective network to carry out malicious activity — in this case, siphoning cryptocurrency from compromised systems. Because these infections can persist for years, businesses that hold or transact in digital currency are particularly attractive targets.

While details on how the takedown was achieved are limited, the news is a reminder that old malware families don't simply disappear — they evolve to chase new opportunities, including the growing use of cryptocurrency by businesses and individuals alike.

botnet cryptocurrency theft malware takedown

Summarised by CISO AI from Cointribune. We link back to every original so you can read it yourself.