Affected Systems
Sality botnet infrastructure (active since 2003), affecting 15,000+ infected devices globally. Primary payload in recent years: EggJagger clipjacking malware targeting cryptocurrency wallets. Botnet operated by SALTY SPIDER threat group, likely based in Bashkortostan, Russia.
Exploitation Status
Botnet was actively operational until takedown in September 2026. For the past 8 years, primarily distributed EggJagger clipjacking malware. Historically delivered credential theft tools, spam distribution, proxy services, network exploitation tools, and DDoS capabilities. Botnet is now disrupted and no longer under operator control.
Business Impact
This is a defensive win—the botnet has been taken down, not a new threat. Organizations previously infected with Sality may still have remnant infections requiring cleanup. The P2P sinkhole operation isolated infected machines by purging peer lists and blocking payload distribution. Primary risk was cryptocurrency theft via clipboard hijacking (EggJagger), though historical payloads included credential stealers and DDoS tools. No immediate threat from this specific botnet, but infected endpoints may remain compromised until remediated.
Urgency
🟡 Within a week
Recommended Actions
- Scan endpoints for Sality malware indicators using updated AV/EDR signatures; CrowdStrike and other vendors should have detection coverage post-takedown
- Review historical network logs for connections to known Sality C2 domains and super peer IPs; correlate with endpoint activity for potential lateral movement or data exfiltration
- Audit cryptocurrency transaction history on potentially infected systems for evidence of clipjacking (unexpected wallet address changes); review clipboard monitoring activity
- Isolate and reimage any confirmed Sality-infected systems; P2P malware often persists through standard cleanup and may have installed additional payloads over 20+ year lifespan
- Block known Sality-related domains and IPs at perimeter firewalls and DNS; coordinate with ISP or security vendor for updated IOC feeds from the takedown operation
