Product1 distinct publisher3 min readPublished
The company found weaknesses in Sality's peer-to-peer design and fed it false information until infected machines dropped their controller. The FBI and Justice Department handled the domain seizures.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
Follow any of these and your For You feed starts watching them — no settings page required.
product
DOJ downgraded its hacking victims to targets two days after the headlines ran1 distinct publisher
security
DoJ rewrites its QTFY seizure release to move seven agencies from victims to targets1 distinct publisher
invest
OpenAI's own model used a package server to get out, and Hugging Face paid for it1 distinct publisher
security
FBI counts 30-plus ransomware disruptions this year, and the target is the plumbing1 distinct publisher
The machine at the centre of this story is one nobody logs into. It sits in a plant room or a back office, running an executable that was infected some time in an earlier decade, and this week it quietly stopped talking to its controller because CrowdStrike convinced it there was no controller left to talk to [4]. Nothing fired an alert, and nothing was cleaned: the host still carries whatever weakness let Sality on in the first place [14].
A domain seizure only reaches the parts of an operation that have addresses [8], and Sality deliberately had few of them, spreading through infected executables and keeping compromised hosts pointed at each other [7]. So the attack ran against trust in a peer list rather than against cryptography. CrowdStrike's Tillmann Werner called it "the most complex botnet takeover we have ever done" [5], announced at the company's Day Zero threat intelligence summit in Las Vegas [6], per The Next Web's account of the operation, which cited Reuters reporting [2].
A 23-year-old crime platform used for spam, DDoS and cryptocurrency theft was retired this week [3][21]. What the operation actually demonstrated is narrower and more durable: a distributed network can be dismantled by persuading its nodes that the controller they trust is gone, no encryption broken and no brute force required [20]. A private company did that inside a criminal network, at a moment when the US has authorised private firms to run cyber operations abroad [12].
Takedowns get scored in domains seized and superlatives at summits. The two numbers a defender would use are the count of infected machines and the losses, and neither was disclosed [13][1]. Shadowserver's David Watson described Sality as a way into a large number of organisations [10], which is a statement about value rather than size, and the source of the botnet's worth was the access it sold onward rather than anything it did itself [21]. No arrests have been announced, and when operators sit outside the reach of the courts doing the work, seizing infrastructure and cutting connections are among the few moves available [11][19].
For the person who has to answer for the unpatched estate on Friday, split the inventory twice: can this machine be patched, and would you notice within a week if it went silent. Patchable and monitored is ordinary operations. Patchable and unmonitored is exactly where Sality lived, because infections persist when nobody notices, nobody patches, or the software keeps running on a system its owner rarely thinks about [17]. Unpatchable and monitored is a compensating-controls problem you have already argued about in a meeting. Unpatchable and unmonitored is a machine you cannot make any statement about at all.
The cell to work is that last one, and moving a box into "monitored" is usually cheaper than patching it. Lasting 23 years took less sophistication than it took staying unnoticed [18]. The signal this week was a host that went quiet, and only the second question in that grid would have caught it.
Ranked by verification strength, evidence, and original report placement.
CrowdStrike reverse-engineered the botnet, identified weaknesses in its structure, and then seeded it with false information that convinced infected machines to disconnect from their controller.
CrowdStrike researcher Tillmann Werner said: "This was the most complex botnet takeover we have ever done."
Sality has been infecting computers since 2003, making it older than the iPhone, Facebook, and much of the security industry now working to dismantle it.
US law enforcement and CrowdStrike began taking Sality apart this week, Reuters reported, according to thenextweb.com.
Infected machines have been used to send spam, launch distributed denial-of-service attacks and steal cryptocurrency, with the criminals shifting between them as different opportunities became profitable.
CrowdStrike announced the operation at its Day Zero threat intelligence summit in Las Vegas.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 2, 2026
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One outlet relaying one stage
Everything here reaches a reader through The Next Web, which is itself passing on a Reuters report and CrowdStrike's summit announcement. The three named voices — Werner, Essayli, Watson — are all parties to the operation or its ecosystem; no seizure warrant, indictment, domain list or telemetry accompanies them. The mechanical account is specific and plausible, which is exactly why its lack of corroboration matters.
Action executed, scope unstated
Something concrete did happen: domains were seized by the FBI and Justice Department, and connections were being severed this week. But there is not one countable output — no host tally, no losses, no figure for machines observed dropping their controller, no remediation numbers. A 23-year-old file infector could be a rounding error or a serious estate, and this reporting cannot tell you which.
Superlative without a scoreboard
"The most complex botnet takeover we have ever done" is the company grading its own homework, from the stage it rents, during a week when AI-threat headlines are taking the oxygen. The technique may well deserve the billing. The gap is the distance between a headline about talking a botnet into unplugging itself and the absence of a single number showing how many machines listened.
Announced from a marketing stage
CrowdStrike chose Day Zero in Las Vegas for this reveal, and a clean takedown story is threat-intelligence sales collateral. The prosecutor's "clear and present danger" line performs a similar function for a case that has produced no arrests. Even the aside about private firms being cleared to operate abroad points the same way: it enlarges the market for the exact capability being demonstrated.
Direction firm, magnitude blank
That a takedown occurred, that domains were seized, and that nobody has been arrested are all stated flatly enough to rely on. Beyond that the story thins fast: the technical account is unverified, the European exposure paragraph rests on assertion, and the policy claim about private cyber operations is unsourced. Enough to act on defensively, not enough to characterise the operation's size or durability.