Cybersecurity · Thursday, 3 September 2026
A botnet survived 23 years by having no headquarters. Its own tidy-up rule switched it off.
Police in four countries and the security firm CrowdStrike cut off more than 15,000 computers running Sality, by feeding false addresses into the lists each infected machine keeps of its neighbours.
23 years
Sality ran without being switched off, from 2003 until Monday
Europol says the police work behind the takedown goes back to 2017
15,000+
infected computers the operator could still reach at the end
they now answer to machines run by CrowdStrike instead
$150,000
stolen by swapping the crypto wallet addresses people copied
CrowdStrike's estimate for that one payload, over about eight years
4 countries
seized the web addresses that fed the botnet new malware
the US, Bulgaria, Hungary and Romania acted on the same day
The lead story — what happened
-
A botnet is a crowd of ordinary computers infected with the same malware and used by one person as if it were a single machine.
[1] -
Sality had been running since 2003. On Monday it was switched off by police in four countries working with the US security firm CrowdStrike.
[1] [3] -
Most botnets have one control server, and seizing it ends them. Sality had none. Every infected machine took its instructions from its neighbours.
[1] -
That design survived 23 years of takedown attempts, because there was nothing central to seize.
[2] -
To stop its list of neighbours filling up with dead machines, each infected computer checked the list about every 40 minutes and dropped whichever addresses stopped answering.
[6] -
CrowdStrike's researchers used that rule. They stripped the real backbone machines out of the lists and fed in addresses of their own.
[4] -
Each infected machine tidied its way into isolation. More than 15,000 were cut off, and they now report to computers CrowdStrike runs.
[1] [4] -
Police in the United States, Bulgaria, Hungary and Romania seized the web addresses that fed the botnet new malware, so nothing new can reach the machines.
[1] [3] -
For about the last eight years Sality's main job was watching for a copied cryptocurrency address and swapping in the operator's own. CrowdStrike puts the take at at least $150,000.
[5] [6] -
Nobody was arrested and no authority named the operator. CrowdStrike believes the person works from the Bashkortostan region of Russia.
[1] -
The machines are cut off but still infected. The Shadowserver Foundation, a non-profit that scans the internet for infected computers, is working through internet providers to get them cleaned.
[4] [2]
Who is involved
-
CrowdStrike
a US security company that hunts attackers for its customers; its researchers took Sality apart and ran the operation that cut the machines off
-
The US Justice Department and FBI
the US prosecutors and federal police; they seized Sality's web addresses in the United States and announced the takedown
-
Police in Bulgaria, Hungary and Romania
they seized the rest of the addresses, the ones hosted in Europe
-
The Shadowserver Foundation
a non-profit that scans the internet for infected machines; it is now working with internet providers to get the 15,000 computers cleaned
-
Sality's operator
never named and never arrested; CrowdStrike believes the person works from the Bashkortostan region of Russia
What is pushing on this
four countries seized its supply addresses at once, though nobody was charged
having no central server stopped every takedown for 23 years, then stopped nothing
Shadowserver is only now telling internet providers which of their customers are infected
How it unfolded
-
2003
Sality appears as a virus that hides inside program files and spreads when they are copied
[1] [5] -
Later
it grows into a network where the infected machines talk to each other, so there is no server to shut down
[1] -
2017
European police start the work that ends in this takedown
[2] -
Monday
CrowdStrike floods the peer lists and the machines lose contact with the operator
[5] [6] -
Tuesday
the US Justice Department announces it
[5]
Where this points
Watch whether the 15,000 cut-off machines actually get cleaned: they are still infected, the operator was never named or arrested, and the only thing standing between the two is an internet provider passing on a warning.
The rest of the day
45 more stories on this beat.
Each with its own sources. None of these is a link to the story above.
-
02
Airport data dumped for free
The criminals who stole records on 8.7 million Manchester Airports Group customers published the whole set online after the company refused to pay. Contact details, car registrations and postcodes were taken through wi-fi and car-parking databases.
[8] [9] Why it matters — Refusing ends the ransom and starts the second problem: passengers at Manchester, London Stansted and East Midlands are being warned of follow-up scams using their own details.
[8] [10] -
03
Carhartt records posted online
The extortion group ShinyHunters published data from 12.9 million Carhartt accounts, according to the breach-tracking service Have I Been Pwned. Carhartt, a US workwear brand founded in 1889, has still not confirmed the theft.
[7] Why it matters — The gang claimed 50GB in mid-August; the published file is the first count anyone outside the gang can check.
[7] -
04
McKesson confirms data was taken
McKesson delivers about a third of the prescription medicines used by hospitals and pharmacies in North America. It told the US markets regulator that attackers took customer data, found on 25 August.
[11] [12] Why it matters — ShinyHunters claims 284 million records and reporting puts the ransom demand at $55m, so the only figures in public are the attackers'.
[11] [13] -
05
9.5 million patients in one breach
Aesto Health told the US health department that a breach reached 9,540,683 people, including names, dates of birth, medical details, bank account numbers and social security numbers.
[14] Why it matters — HIPAA Journal says the breach indirectly reaches 29 healthcare providers, so it lands on patients who chose their clinic and never heard of Aesto.
[14] -
06
Second emergency patch for PaperCut
PaperCut, print software used by schools, councils and companies, issued a second emergency fix after the first was bypassed, and named two flaws that can be chained together.
[15] [18] Attackers moved from probing to real break-ins, and one is copying database tables rather than planting malware.[16] [17] Why it matters — The internet watchdog Shadowserver still counts more than 800 exposed PaperCut servers.
[16] -
07
Attackers mint their own admin passes
A flaw in JFrog Artifactory, the shelf where companies keep the software parts they build with, lets a stranger with no login forge administrator tokens. It was patched on 28 August and attacked within days.
[19] [20] [21] Why it matters — Security firm watchTowr saw attackers minting themselves admin access, and an admin on that shelf can poison packages that thousands of other companies then download.
[19] [20] -
08
SonicWall remote-access boxes attacked
SonicWall says two flaws in its SMA1000 boxes are being chained together in live attacks, and told customers to rebuild the machines and reset every password. Shadowserver counts more than 400 exposed online.
[22] [23] Why it matters — These are the boxes staff log in through, so one of them is a door into a whole office network.
[23] -
09
Three top-severity ServiceNow flaws
ServiceNow, the software many large companies run their IT and HR requests on, patched three flaws rated at the maximum severity score and said it has seen no attacks yet.
[24] Why it matters — Two years ago attackers chained three ServiceNow flaws to break into firms and governments worldwide, so the gap between patch and attack is the thing to watch.
[24] -
10
WatchGuard fixes five critical flaws
Firewall maker WatchGuard patched more than two dozen flaws, five of them critical, including three in the part of its system that sets up encrypted connections for remote staff.
[25] Why it matters — It says it knows of no attacks yet, which is the difference between this and the SonicWall case the same week.
[25] [22] -
11
Office phone systems broken into
Attackers are exploiting a flaw in Sangoma Switchvox, a business phone system, to run commands on the server. Researchers at Horizon3 saw their decoy machines hit in rapid succession on 30 August.
[26] Why it matters — The flaw was reported in April and fixed on 14 July, so every machine hit was six weeks behind.
[26] -
12
AI-builder tool under attack
A flaw in Langflow, a tool for wiring together AI assistants, is being exploited. VulnCheck saw more than 50 hits on its decoy systems in a single morning, mostly from addresses in Russia, looking for stored logins.
[27] Why it matters — The flaw was made public in January, so this is an old hole being used on people who never closed it.
[27] -
13
Five critical WordPress flaws
Researchers listed five flaws in widely used WordPress plugins and themes rated 9.8 out of 10, including one that hands a visitor with no login full administrator control of a site.
[28] Why it matters — Most small-business and charity websites run WordPress, and update it when somebody remembers.
[28] -
14
A Lenovo login opened Dropbox accounts
Dropbox told about 5,000 users that someone got into their accounts without a password, by registering a Lenovo ID using their email address. Dropbox took Lenovo's word that the person owned the address.
[29] [30] Why it matters — Several of the victims had never had a Lenovo account at all, and Dropbox has now cut the old link.
[30] -
15
$600,000 of AI credits, unnoticed
METR, a non-profit that tests AI models for dangerous behaviour, said an attacker stole one of its keys in March and spent about $600,000 of model credits over roughly three weeks before anyone noticed.
[31] [32] Why it matters — The model provider waived the bill. A paying customer would have received it.
[31] -
16
Stolen sessions used to run AI free
Anthropic told users that ordinary password-stealing malware already on their own computers had taken their logged-in Claude sessions, and that strangers were spending the victims' paid usage.
[33] [34] Why it matters — The break-in was not in the AI service, it was on the customer's laptop, and Anthropic signed the affected users out and removed their saved cards.
[33] -
17
AI agents ran a whole break-in
Palo Alto Networks described a ransomware attack in which a person directed AI models through every step and got into a company network in under ten hours, work it says normally takes about two weeks. The attacker then left the victim an 80-page security report.
[35] Why it matters — The claim about the tools comes from the attacker's own messages to the negotiators, so the timing is the checkable part.
[35] -
18
Coding assistant used to hack seven firms
Israeli firm Gambit says it read 28 chat sessions on a server a new ransomware crew called Aur0ra left open by mistake, showing Russian-speaking criminals using the AI coding tool Cursor to break into seven companies.
[36] Why it matters — Cursor and its owner did not answer questions, and the whole account rests on that one exposed server.
[36] -
19
Security firm calls it a turning point
The head of Palo Alto Networks' threat-intelligence arm said easily available AI agents have broken the rough balance between attackers and defenders, calling it a generational shift.
[37] Why it matters — That is a vendor's assessment rather than a measurement, and it lands the same week as two AI-assisted intrusions that do have evidence behind them.
[37] [35] -
20
Rival tech firms sign a defence pledge
An open letter led by OpenAI and signed by large technology and security companies warns that AI-assisted attacks will get sharply more capable within months. It names hospitals, water treatment plants and internet infrastructure as the exposed ones.
[38] Why it matters — A pledge is not a rule, and the letter asks for spending nobody has promised.
[38] -
21
US corrects its own hacking claim
The US Justice Department edited a statement that had named NASA, the US Federal Reserve, the US Energy Department and the US Senate as victims of a Chinese hacking platform called QTFY. They are now described as among its targets.
[39] [40] Why it matters — Being aimed at and being broken into are very different, and the first version ran as headlines for two days.
[40] -
22
Routers used as launch pads
The incident-response firm Sygnia says a Chinese group it calls Fire Ant took over Cisco routers and login servers and used them to reach further networks, collecting passwords as it went.
[41] Why it matters — The equipment it took over is the sort most organisations file under legacy and stop watching.
[41] -
23
Spies move from email to chat apps
The European Union confirmed that state-backed hackers are sending targeted lures to its officials on Signal and WhatsApp rather than by email, and EU governments are trying to move officials off those apps.
[42] Why it matters — Staff expect suspicious mail in an inbox. A message on a phone arrives where nobody is checking.
[42] -
24
New backdoor aimed at Europe
Recorded Future linked a previously undocumented backdoor it calls HOOKEDGE to APT28, a Russian state hacking group, delivered inside Word documents dressed up as diplomatic paperwork. Early versions imitated Spanish government material.
[43] Why it matters — The link rests on code overlap with an older tool, and Recorded Future rates its own confidence as moderate.
[43] -
25
Foreign spies rising fast in Germany
A survey of 1,003 German companies by the industry body Bitkom found the share blaming foreign intelligence services for attacks rose from 7% in 2023 to 28% last year, and higher again this year. China was named most often, then Russia.
[44] Why it matters — Only organised crime is now blamed more often, and Germany's domestic intelligence chief says defence firms are the favourite target.
[44] -
26
Nuclear agency files on an open server
Researchers at Hunt.io found 1,310 files, nearly 1.2GB, on an attacker's server in Amsterdam, including data from a Philippine nuclear agency and a shipbuilder that serves the country's navy.
[45] Why it matters — The way in was old unpatched flaws; the folder names were in Chinese, and Hunt.io stopped short of naming anyone.
[45] -
27
US bars foreign-made grid equipment
An order signed by US President Donald Trump bans buying or installing foreign-made bulk-power equipment from designated suppliers, covering transformers, inverters and the controllers that run power lines carrying 69,000 volts or more.
[46] [47] Why it matters — It names no country but copies the shape of a 2020 order aimed at China, and follows a four-day shutdown of a small British power plant.
[46] [47] -
28
UK bill would block risky suppliers
A UK bill close to becoming law would let the UK government keep high-risk technology suppliers out of critical infrastructure. It has passed the House of Commons and is now in the House of Lords.
[48] Why it matters — A four-day shutdown at a small UK energy site, reported on 22 August, is what raised the question of wider supply-chain attacks the bill is meant to cover.
[48] -
29
Free defence for Texas water utilities
The US national cyber director's office started a six-month pilot in Texas giving water and wastewater utilities free defensive help, with Microsoft, Google, AWS, Cloudflare, Palo Alto Networks, Forescout and Dragos taking part.
[49] Why it matters — Rural water providers often lack the resources to defend themselves, and more than 100 water systems were reported targeted in a single week's round-up.
[49] [69] -
30
Slovenian casinos reopen after attack
Hit, which runs casinos and hotels in Slovenia and Bosnia and Herzegovina, reopened six casinos after an attack closed them for about three days. Some games and its loyalty system were still down.
[50] Why it matters — Guests were held to a handful of slot machines while systems came back, which is what a recovery actually looks like.
[50] -
31
Ransomware claim, then a class action
Nutex Health, a healthcare company based in Houston, said someone is threatening to publish stolen information, and told the US markets regulator that a proposed class action has already been filed in Texas. The Gentlemen ransomware group claimed it on Monday.
[51] Why it matters — The lawsuit arrived before the company could say what was taken.
[51] -
32
Charged over 80,000 booby-trapped spreadsheets
A 40-year-old Russian man extradited from Cyprus appeared in a San Francisco court. He is accused of using about 255 fake accounts on a freelance work platform to send malware-laced Excel files to roughly 80,000 of its users in 2016 and 2017.
[52] Why it matters — The charges were filed in 2021 and unsealed only now, five years after they were written.
[52] -
33
Donor lists taken from Russian charities
Two Russian projects that raise money for Ukrainian civilians and for political prisoners said attackers reached their donor data through a payments link. The payments firm Stripe cut the access before the full list of email addresses could be copied.
[53] Why it matters — The projects say they cannot yet tell whether this was ordinary criminals or Russian security services.
[53] -
34
Record scam losses, and little help
Americans reported $15.9bn of scam losses last year, a 25% rise, and the US Federal Trade Commission believes the real 2024 figure was closer to $200bn, about $550m a day. An Associated Press and FRONTLINE investigation interviewed 58 victims who each lost between a few thousand dollars and $4m.
[54] [55] Why it matters — One of the 58 got money back. Many were then taxed on the retirement savings the scammers took.
[55] -
35
The scam where your bank is the scammer
A text saying a new payment has been set up, with a number to ring, is the shape of the impersonation scam costing British customers most. Lloyds figures show fraudsters posing as banks, the police and the tax office.
[56] Why it matters — The text names a real bank so it looks genuine, and the number in it is the fake part. One target strung a caller along for three hours.
[56] [57] -
36
Scammers set up shop on Microsoft Teams
WIRED reported that romance and investment scammers in China are moving victims onto Microsoft Teams and handing them a ready-made account and password. One woman in Beijing lost more than $100,000.
[58] Why it matters — The brand did the work. She said she trusted it because Microsoft built it.
[58] -
37
Phone calls through Teams to plant software
Palo Alto Networks described an operation it calls Spring Ring. It phoned at least 150 Microsoft Teams users at ten or more companies and talked them into installing remote-control software. In some cases it then went after the company's main login servers.
[59] Why it matters — Attacks are moving from email to the company's own chat tools, which make the approach look authentic.
[59] -
38
Fake streaming app sold through Meta ads
ThreatFabric found Android malware it calls StreamRat advertised through Meta's ad system. Once installed and granted accessibility permissions, it can record what is typed, show fake login screens and control the phone.
[60] Why it matters — The stopping point is plain: a streaming app asking for system-wide controls is asking for the phone.
[60] -
39
Control addresses hidden on a blockchain
GuidePoint Security says a Clickfix campaign has compromised the websites of 31 organisations in online retail, professional services and logistics, and keeps the addresses it takes orders from on the Polygon blockchain.
[61] Why it matters — Blocking a fixed address used to end a campaign; a ledger entry can be rewritten instead.
[61] -
40
Rented hacking kit claims 48 victims
CRPx0, which sells break-in services to people who cannot do it themselves, says its victim count went from fewer than 10 in June to 48 organisations. The figure is the gang's own claim on its own leak site.
[62] Why it matters — Criminals inflate, and the growth rate is still the fastest thing on that page.
[62] -
41
Call blocker fined for nuisance calls
The UK's data protection watchdog fined Elderly Aids Ltd 190,000 pounds for making about 758,000 unwanted calls a year to elderly people. It was selling equipment to stop unwanted calls.
[63] Why it matters — The company sold its product by doing the exact thing the product claims to stop.
[63] -
42
Meta's new limits for under-18s
As part of an $18bn settlement with 48 US states, Meta will hold under-18 users to two hours a day, block its apps between midnight and 6am, hide like counts and tighten age checks. The changes apply only in the United States and most last ten years.
[64] Why it matters — A former Meta engineering director said the deal lets Meta decide what counts as harm.
[64] -
43
US agency took a journalist's phone records
The Guardian reported that the US Department of Homeland Security is using a little-known summons power to obtain records on journalists, non-profits and unions without telling them. In one case it took six months of phone records for a Minneapolis journalist.
[65] Why it matters — A judge had twice refused search warrants for the same journalist's accounts, saying US prosecutors had not shown probable cause.
[65] -
44
Asked 100 companies for data, got deletions
A WIRED reporter used California's privacy law to file more than 100 requests for the data companies hold on them. McDonald's returned a 515-page file; several companies responded by deleting the account instead.
[66] Why it matters — The right exists and the process defeats it, which is a different problem from having no right.
[66] -
45
Finland revives undersea cable case
A Finnish appeals court reinstated a case against officers of the tanker Eagle S over broken power and telecoms cables, ruling the crimes happened in Finland because the damage landed there. It also ruled the events were not a maritime accident.
[67] Why it matters — That ruling closes the defence's route to the ship's flag state, after a maritime law professor warned the earlier judgment meant cables could be cut with no consequences.
[67] -
46
Nine cash machine flaws, one bigger point
Security researcher Matt Burch presented nine flaws in the encryption and authentication software inside cash machines, and argued the same code is used well beyond banking.
[68] Why it matters — The cash machine is the demonstration. The point is everywhere else that software sits.
[68]
The rule that kept it tidy was the way in
A network with no leader decides who is still in it by asking who answers, so anyone who can silence the answers can empty it.
The twist
The rule that stops a leaderless network filling with the dead is the only lever needed to empty it, because that rule accepts silence as proof.
How it works
- A botnet with one control server dies the day that server is seized
- So Sality gave every infected machine a list of its neighbours instead
- Those lists would fill with dead computers, so each machine re-checks them
- Neighbours that answer are kept; neighbours that go quiet are dropped
- Investigators made the real neighbours stop answering, and fed in addresses of their own
- Each machine tidied its way into isolation, using the rule that kept it healthy
Where you've seen this
A club's membership list
strike off anyone who misses two meetings, and stopping the letters is enough to empty the club
Search engines
a page that stops answering is quietly dropped from results, so blocking a site can make it disappear
Your phone's contacts
an app that clears out people who never reply will delete the friend who lost their phone
The catch
It worked because silence counted as proof. Demanding a signed answer instead would need somebody to keep the keys, which is the leader the design existed to avoid.
And the whole of it
The 15,000 machines were ordinary computers in homes and offices, and their owners still do not know they were in it. Almost every list that decides who is in and who is out is kept by a rule nobody reads, and from inside one you can only see your own line.
What is really going on
The Sality operation is being announced as law enforcement winning, and what actually happened is that a security company reverse-engineered a botnet, nobody was arrested, and 15,000 computers are still infected.
Why it works on us — A takedown is announced as an ending because an ending has a date and a name in it, and the years of clean-up afterwards have neither.
Who gains
-
CrowdStrike
— It did the technical work and published the write-up, so its own blog is the source every account of the takedown quotes.
[1] [6] -
ShinyHunters
— Publishing the Carhartt file and attaching a reported $55m demand to McKesson makes the next company's board read the threat as real.
[7] [11] [13] -
Prosecutors in the US, Bulgaria, Hungary and Romania
— Four countries seized domains on one coordinated day and announced it together, which is the visible half of work Europol dates to 2017.
[2] [3] -
Makers of US-built grid equipment
— The new order bars designated foreign-made transformers, inverters and controllers from high-voltage US power lines, leaving those orders to be placed elsewhere.
[46] [47] -
The security firms in the Texas water pilot
— Microsoft, Google, AWS, Cloudflare, Palo Alto Networks, Forescout and Dragos supply the tools free for six months to utilities that have never bought any.
[49]
Who pays
-
The 9.5 million people in the Aesto Health file
— Names, medical details, bank account numbers and social security numbers were taken from a supplier their own clinic chose, not one they picked.
[14] -
Passengers at Manchester, London Stansted and East Midlands
— Their details were published free once the ransom was refused, so the file is now available to anyone who wants it.
[8] [9] -
Owners of the 15,000 cut-off computers
— The machines are isolated but still infected, and getting them cleaned depends on an internet provider passing on a warning.
[1] [4] -
About 5,000 Dropbox users
— Their accounts were opened without a password because Dropbox took Lenovo's word about who owned an email address.
[29] [30] -
Scam victims in the United States
— They reported $15.9bn of losses last year, are often taxed on the retirement money that was taken, and of 58 interviewed by reporters, one got money back.
[54] [55]
What nobody knows yet
Open questions from across today’s stories — ours included.
-
01
Who ran Sality.
CrowdStrike says the operator works from the Bashkortostan region of Russia. No arrests were announced and no authority has named a person.
[1] [2] -
02
How many computers Sality actually infected.
CrowdStrike counts more than 15,000 machines the operator could still reach at the end. CyberScoop reports the botnet infected more than 11 million devices across its 23-year run. The two numbers are not measuring the same thing, and nobody has published a reconciliation.
[1] [2] -
03
Whether the 15,000 machines get cleaned.
Shadowserver is only now telling internet providers which addresses are infected, and nothing in the announcement obliges a provider or an owner to act.
[2] [4] -
04
What was taken from McKesson.
The company confirmed data was taken from two of its business units and has not said what, how much, or from how many people. ShinyHunters' claim of 284 million records is the only figure in public.
[11] [12] [13] -
05
Whether anything was actually taken from the US agencies in the QTFY case.
The US Justice Department first called NASA, the US Federal Reserve and the US Senate victims, then edited the statement to say they were among the targets, and did not explain the change.
[39] [40] -
06
Who broke into the Philippine nuclear agency.
Hunt.io found the stolen files on a server left open in Amsterdam, with Chinese-language folder names and code comments, and declined to name anyone.
[45] -
07
Whether the AI-run ransomware attack happened the way it was described.
The claim that frontier AI models carried out every step comes from the attacker's own messages to the victim's negotiators.
[35] -
08
How much of the published Carhartt data is genuine.
ShinyHunters claimed 50GB in mid-August, the published set covers 12.9 million accounts, and Carhartt has confirmed nothing.
[7]
The work that ended Sality began in 2017. Nine years later four countries seized its addresses on the same day, and a non-profit is now going internet provider by internet provider to tell 15,000 people their computer was infected.
More from Cybersecurity