Long-Running Sality Botnet Dismantled After Years of Crypto Theft
The Sality botnet, active for eight years, has been dismantled following a joint operation involving cybersecurity firm CrowdStrike and the U.S. Department of Justice. The botnet had compromised approximately 15,000 machines worldwide, using them to steal Bitcoin and Ethereum from victims without their knowledge.
Botnets like Sality operate by quietly infecting computers and enlisting them into a network controlled by attackers, often for cryptocurrency theft, spam distribution, or further malware spread. Because infections can persist for years before detection, victims may be unaware their systems have been compromised and used for criminal activity.
The takedown highlights the value of coordinated action between private security firms and law enforcement in disrupting long-running cybercrime operations. For small businesses, it also serves as a reminder that older or unpatched systems can be silently exploited for extended periods without obvious warning signs.