International law enforcement agencies and private-sector partners have seized Sality malware infrastructure, a long-running peer-to-peer malware botnet, BleepingComputer reports. The operation targeted domains and control channels used by the botnet, with CrowdStrike saying the network is no longer under the operator’s control. According to BleepingComputer, the U.S. Department of Justice, FBI, and Defense Criminal Investigative Service seized Sality-linked domains in the United States. Law enforcement partners in Bulgaria, Hungary, and Romania seized additional domains hosted in Europe. CrowdStrike’s Counter Adversary Operations team also participated in the action alongside law enforcement and private industry partners, BleepingComputer reports. The company helped dismantle the botnet’s control channels through a peer-to-peer sinkhole operation intended to isolate infected machines. The peer-to-peer structure matters because Sality did not rely on a simple, centralized command-and-control model. BleepingComputer reports that the takedown sinkholed Sality’s known “super peers,” which formed the botnet’s communications backbone. The goal was to stop file packs and URL packs from propagating and to purge infected machines’ peer lists. Sality is unusually old by malware standards. BleepingComputer reports that it first surfaced in 2003, has been active for more than two decades, and has infected more than 15,000 devices. CrowdStrike attributes the botnet to a criminal group it tracks as SALTY SPIDER, which it says is likely operating from the Republic of Bashkortostan in Russia. The botnet’s use has changed over time. BleepingComputer reports, citing CrowdStrike, that Sality has historically distributed malware used for credential theft, spam, proxy services, network exploitation, and distributed denial-of-service attacks. In the past eight years, CrowdStrike says its primary payload has been EggJagger, a clipjacking tool that watches for cryptocurrency wallet addresses in the clipboard and replaces them with addresses controlled by the operator. The most recent Sality activity described in the report involved two still-active botnet networks. CrowdStrike told BleepingComputer those networks were mainly being used to push EggJagger payloads in clipjacking attacks. The action fits a broader pattern of multinational cybercrime disruption this year, but the provided reporting does not establish whether Sality infections have been fully remediated. The concrete change is narrower and still significant: law enforcement seized Sality-linked domains, while CrowdStrike and partners say they disrupted the peer-to-peer botnet’s control channels. Who benefits: Enterprises and consumers with infected machines may benefit if the sinkhole operation prevents Sality from receiving new payload instructions. Cryptocurrency users may also be less exposed to the specific EggJagger clipjacking activity described by CrowdStrike if the disruption holds. Who's exposed: Organizations with unmanaged or long-infected endpoints remain exposed if machines are still compromised, even if the botnet’s control channel has been disrupted. The provided reporting does not say every infected device has been cleaned.