ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

International Operation Disrupts Sality P2P Botnet

mediumMalwareimportance 62
AI summary · glm-5.3-flash

US-led international operation with Europol, CrowdStrike, and Shadowserver sinkholed the 20-year-old Sality P2P botnet, once exceeding one million infected machines.

On August 31, 2026, authorities from the US, Bulgaria, Hungary, and Romania, supported by Europol, CrowdStrike, and the Shadowserver Foundation, disrupted the Sality P2P botnet by sinkholing communications and seizing domains. Sality has operated for over 20 years, at its peak controlling more than one million infected machines used for credential theft, spam, proxy services, crypto-theft, and DDoS attacks, with over 11 million unique IP addresses linked to its infrastructure since 2017. The disruption exploited the botnet's super-peer reputation mechanism by removing legitimate peers via protocol-level manipulation and inserting sinkhole entries into emptied peer lists.

  • August 31 operation coordinated by US, Bulgaria, Hungary, Romania with Europol support
  • Sality ran 20+ years, peaked at over one million infected machines
  • More than 11 million unique IPs linked to infrastructure since 2017
  • Disruption exploited super-peer reputation checks via protocol manipulation
  • Shadowserver coordinated ISP and CSIRT victim notification and remediation
Full article458 words · extracted from infosecurity-magazine.com · click to collapse

A P2P botnet thought to have been running for over two decades, has suffered significant disruption thanks to a US-led law enforcement operation.

Carried out on August 31, the operation against the Sality botnet brought together authorities from Bulgaria, Hungary, Romania, and the US, with the support of Europol as well as private-sector partners CrowdStrike and the Shadowserver Foundation.

A big part of the disruption activity focused on “sinkholing” – the process of redirecting communications from infected machines away from the botnet infrastructure.

This was necessary because of the way that P2P botnets operate: machines communicate with each other in a decentralized fashion rather than with a single command and control (C2) server, making the infrastructure harder to disrupt.

Read more on P2P botnets: Novel Worm-Like Malware P2Pinfect Targets Redis Deployments.

Europol said the operation had been a long time coming. It has supported efforts to identify and take down infrastructure linked to Sality around the world since 2017.

“In the weeks leading up to the latest disruption, this cooperation intensified, with partners holding weekly operational calls to coordinate their actions,” the policing organization continued. “Europol supported the involvement of law enforcement authorities in Bulgaria, Hungary and Romania, helping to coordinate measures against the botnet infrastructure across the different jurisdictions.”

While authorities in the US and Europe focused on seizing Sality-linked domains, the Shadowserver Foundation coordinated with ISPs and Computer Security Incident Response Teams (CSIRTs) to identify infections, notify victims, and help with remediation, the US Justice Department said.

20 Years and Counting

According to Europol, Sality has been operating for more than 20 years, and at its peak featured over one million infected machines unwittingly conscripted into criminal efforts to distribute malicious payloads for crypto-theft and other attacks.

Over the course of the past two decades, more than 11 million unique IP addresses have been linked to the infrastructure, it added.

CrowdStrike claimed the botnet enabled its operator to distribute malicious payloads to over 15,000 infected machines. These spanned credential theft, spam distribution, proxy services, network exploitation and DDoS attacks, it said.

Exposing Sality's Trust Flaw

The security vendor explained that the operation to disrupt Sality leveraged the fact that machines trust the network without verifying who is in it.

“Every Sality bot maintains a finite list of known super peers, which are publicly reachable infected machines that form the backbone of the P2P network,” it continued. “Every 40 minutes, it verifies whether its stored peers are still online. Peers that respond accumulate reputation; those that fail to respond lose reputation and are eventually purged.”

The disruption took advantage of this to:

  • Remove legitimate peers via protocol-level manipulation during peer verification
  • Insert sinkhole entries into the emptied peer lists to enable progress tracking and victim notification

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/international-operation-disrupts/