← All stories
● Covered by 3 sources · 3 reportsMedium impact2 neutral1 positive

Sality P2P Botnet Dismantled After 23 Years of Operation

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Sality botnet, active since 2003, has been disrupted.
  • Operation involved U.S., Bulgaria, Hungary, Romania, and private partners.
  • P2P sinkhole and domain seizures were used to neutralize the threat.
  • Botnet infected over 15,000 devices and distributed malware.
  • EggJagger tool, associated with Sality, stole at least $150,000 in crypto.

International Effort Disrupts Sality Botnet

The Sality peer-to-peer (P2P) botnet, which has been active for 23 years, was disrupted as part of a coordinated international law enforcement operation. The U.S. Department of Justice (DoJ), along with authorities from Bulgaria, Hungary, and Romania, collaborated with private industry partners CrowdStrike and the Shadowserver Foundation to execute the takedown on August 31, 2026.

This effort involved a P2P sinkhole operation to eliminate the threat and the seizure of Sality-linked domains in the U.S. and Europe. Europol, Eurojust, the FBI, and DCIS also supported the operation.

Sality's Long History and Capabilities

First observed in 2003, the Sality botnet has infected over 15,000 devices. It is known for its ability to infect and modify Windows executable files and spread additional malicious software. Its capabilities included credential theft, spam distribution, proxy services, network exploitation, and distributed denial-of-service (DDoS) attacks.

For the past eight years, Sality primarily served the EggJagger clipjacking tool, which is believed to have stolen at least $150,000 in Bitcoin and Ethereum.

Overcoming P2P Architecture

Sality's P2P architecture allowed it to persist for over two decades, as it did not rely on a central command-and-control (C&C) server. It spread by attaching itself to executables on disk and removable media. The botnet's resilience stemmed from its ability to blindly trust peers on the network without authentication or identity verification.

The disruption exploited this very behavior. Sality bots periodically checked the accessibility of peers in their list of super peers. By manipulating this process, the operation isolated infected machines and dismantled the botnet's control channels.

Significance of the Takedown

The successful takedown prevents the botnet from distributing new malware payloads and removes a long-standing threat from the cyber landscape. This operation demonstrates the effectiveness of public and private sector collaboration in combating cybercrime.

CrowdStrike tracks the criminal group controlling Sality as SALTY SPIDER, which is likely operating out of the Republic of Bashkortostan in Russia.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~24 min · 20 stories · Sep 01

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

The Sality peer-to-peer (P2P) botnet, active since 2003, has been disrupted through an international law enforcement effort coordinated with CrowdStrike. This disruption ends the botnet's ability to distribute malware and steal cryptocurrency, marking a significant success against a long-standing cyber threat.

International law enforcement agencies and private partners have dismantled the Sality peer-to-peer botnet infrastructure, which has been active for over two decades and infected more than 15,000 devices. This operation involved seizing Sality-linked domains and sinkholing the botnet's control channels, effectively isolating infected machines and disrupting its operations. The takedown prevents the botnet from distributing malware, including the EggJagger clipjacking tool, and removes a long-standing threat from the cyber landscape.

The U.S. Department of Justice, alongside international partners and private companies, announced the takedown of the Sality peer-to-peer botnet. This operation involved a P2P sinkhole and domain seizures, effectively neutralizing a long-standing threat that bypassed traditional command-and-control shutdown methods.