The Sality peer-to-peer (P2P) botnet, which has been active for 23 years, was disrupted as part of a coordinated international law enforcement operation. The U.S. Department of Justice (DoJ), along with authorities from Bulgaria, Hungary, and Romania, collaborated with private industry partners CrowdStrike and the Shadowserver Foundation to execute the takedown on August 31, 2026.
This effort involved a P2P sinkhole operation to eliminate the threat and the seizure of Sality-linked domains in the U.S. and Europe. Europol, Eurojust, the FBI, and DCIS also supported the operation.
First observed in 2003, the Sality botnet has infected over 15,000 devices. It is known for its ability to infect and modify Windows executable files and spread additional malicious software. Its capabilities included credential theft, spam distribution, proxy services, network exploitation, and distributed denial-of-service (DDoS) attacks.
For the past eight years, Sality primarily served the EggJagger clipjacking tool, which is believed to have stolen at least $150,000 in Bitcoin and Ethereum.
Sality's P2P architecture allowed it to persist for over two decades, as it did not rely on a central command-and-control (C&C) server. It spread by attaching itself to executables on disk and removable media. The botnet's resilience stemmed from its ability to blindly trust peers on the network without authentication or identity verification.
The disruption exploited this very behavior. Sality bots periodically checked the accessibility of peers in their list of super peers. By manipulating this process, the operation isolated infected machines and dismantled the botnet's control channels.
The successful takedown prevents the botnet from distributing new malware payloads and removes a long-standing threat from the cyber landscape. This operation demonstrates the effectiveness of public and private sector collaboration in combating cybercrime.
CrowdStrike tracks the criminal group controlling Sality as SALTY SPIDER, which is likely operating out of the Republic of Bashkortostan in Russia.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The Sality peer-to-peer (P2P) botnet, active since 2003, has been disrupted through an international law enforcement effort coordinated with CrowdStrike. This disruption ends the botnet's ability to distribute malware and steal cryptocurrency, marking a significant success against a long-standing cyber threat.
International law enforcement agencies and private partners have dismantled the Sality peer-to-peer botnet infrastructure, which has been active for over two decades and infected more than 15,000 devices. This operation involved seizing Sality-linked domains and sinkholing the botnet's control channels, effectively isolating infected machines and disrupting its operations. The takedown prevents the botnet from distributing malware, including the EggJagger clipjacking tool, and removes a long-standing threat from the cyber landscape.
The U.S. Department of Justice, alongside international partners and private companies, announced the takedown of the Sality peer-to-peer botnet. This operation involved a P2P sinkhole and domain seizures, effectively neutralizing a long-standing threat that bypassed traditional command-and-control shutdown methods.