TechNewsReel
Live

US Authorities and CrowdStrike Dismantle Decades-Old Sality Botnet

Federal officials and private security partners neutralized a persistent malware network used to steal cryptocurrency from digital wallets.

TechNewsReel Newsroom · September 2, 2026

US federal authorities, including the Justice Department and the FBI, have partnered with cybersecurity firm CrowdStrike to disrupt a sophisticated malware operation targeting cryptocurrency users. The joint effort focused on neutralizing the infrastructure of a threat actor network designed to drain funds from digital wallets.

The operation specifically targeted the Sality botnet, a persistent threat that has remained active for more than two decades. According to reports from Cointelegraph and other industry outlets, authorities and their private-sector partners dismantled the network by poisoning the botnet's communication channels and diverting malicious traffic into sinkholes, effectively rendering the infrastructure useless for the attackers.

The Persistence of Sality

Sality is one of the oldest known botnets, having evolved over twenty years to maintain a foothold in infected systems. While originally designed for broader system compromise, the botnet was increasingly leveraged to target the blockchain space. By infecting user devices, the malware could gain access to digital wallets and steal cryptocurrency, exploiting the inherent irreversibility of blockchain transactions to secure illicit gains.

A Shift in Law Enforcement Strategy

This operation underscores a growing trend in US federal law enforcement: the increasing reliance on private cybersecurity firms to combat financial crime. Because threat actors often operate across borders using encrypted and decentralized infrastructure, the specialized telemetry and global visibility provided by firms like CrowdStrike are now essential for identifying and dismantling the technical backends of these operations.

Future Outlook

While the neutralization of the Sality infrastructure marks a significant victory against a legacy threat, the broader landscape of crypto-theft remains volatile. Law enforcement continues to monitor for the emergence of new botnets and the evolution of wallet-draining techniques. It remains to be seen if this disruption will lead to the identification and prosecution of the individual operators behind the Sality network.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.