U.S. and European Authorities Disrupt Notorious Sality Botnet in Coordinated Operation
In a coordinated operation announced on August 31, U.S. and European authorities, including the DOJ, Europol, and agencies from Bulgaria, Hungary, and Romania, disrupted the peer-to-peer Sality botnet—active since at least 2003—by deploying a sinkhole technique to isolate infected machines from suspected Russia-based operators, seizing domains and payload URLs; CrowdStrike and Europol reported cutting off over 15,000 and potentially millions of infected IP addresses, respectively, with the botnet historically used for credential theft, spam, DDoS attacks, and particularly in the last eight years, the EggJagger clipjacking malware that stole at least $150,000 in cryptocurrency by swapping wallet addresses on infected devices’ clipboards.
The Takedown That Wasn't
Twenty-three years. They let Sality run for nearly a quarter-century, harvesting credentials, hijacking clipboard wallets, burrowing into networks across the globe — and only now, with a coordinated splash of press releases and interagency photo-ops, do they "disrupt" it. You have to ask yourself: what changed? The answer is obvious to anyone who has tracked the lifecycle of these so-called botnet takedowns. They are not operations of law enforcement. They are operations of asset retirement. Sality wasn't a criminal enterprise that evaded capture — it was an intelligence pipeline, quietly maintained by the same agencies that now posture as its conquerors. The $150,000 in cryptocurrency stolen via EggJagger is laughable pocket change; the real value was the persistent backdoor into millions of machines, a surveillance lattice that allowed certain actors — and I mean certain actors — to read, redirect, and record at will. You don't "sinkhole" something like that unless you've already copied every byte and severed every thread you no longer need.
The Centralization Deception
Look closer at the technical language they're feeding the press. "Peer-to-peer sinkhole technique" — that's a contradiction designed to confuse. A sinkhole by its nature funnels traffic into a single point, which means the decentralized resilience they spent decades warning us about has been swapped for centralized control under the very authorities claiming to fight it. CrowdStrike, the private company that announced the feat, is itself a creature of the deep state: funded by venture capital tied to intelligence community alumni, its executives rotate through government advisory roles like clockwork. The Sality takedown isn't a disruption; it is a handover. Every infected machine that Shadowserver is now "cleaning up" is actually being re-registered, re-tooled, re-purposed. The real operators haven't gone anywhere. They've simply changed their uniforms. And notice the timing: this announcement lands just as a new round of election interference narratives is being prepared. Coincidence? There are no coincidences.
Who Got Paid to Walk Away
The attribution to SALTY SPIDER and the Republic of Bashkortostan is a classic managed-narrative breadcrumb — specific enough to satisfy the curious, vague enough to never be verified. Russia is always the convenient villain, the perfect foil for a bureaucratic power grab. But I've seen the documents. I've traced the IP handoffs, the shell company registrations, the foundation grants that preceded every major "cybercrime" disruption of the past decade. Sality's operators were never in Ufa. They were in buildings with no signage, in cities with no extradition treaties that matter — and they were paid, quietly, to move on. The question you must sit with is this: if the botnet's clipjacking component alone stole only $150K over eight years, and if the operation cost taxpayers millions, then who really profited? The answer is written in the silence between the press release paragraphs. They want you to think it's over. It never ends.