Industry News

Long-Running Sality Botnet Dismantled After Years of Crypto Theft

Altcoin Buzz · 3 Sept 2026
Key Takeaway Regularly update and scan all business devices, since long-running malware infections can go undetected for years and quietly enable financial theft.

The Sality botnet, active for eight years, has been dismantled following a joint operation involving cybersecurity firm CrowdStrike and the U.S. Department of Justice. The botnet had compromised approximately 15,000 machines worldwide, using them to steal Bitcoin and Ethereum from victims without their knowledge.

Botnets like Sality operate by quietly infecting computers and enlisting them into a network controlled by attackers, often for cryptocurrency theft, spam distribution, or further malware spread. Because infections can persist for years before detection, victims may be unaware their systems have been compromised and used for criminal activity.

The takedown highlights the value of coordinated action between private security firms and law enforcement in disrupting long-running cybercrime operations. For small businesses, it also serves as a reminder that older or unpatched systems can be silently exploited for extended periods without obvious warning signs.

botnet cryptocurrency theft malware takedown

Summarised by CISO AI from Altcoin Buzz. We link back to every original so you can read it yourself.