International law enforcement, CrowdStrike, and Shadowserver disrupt 23-year-old Sality P2P botnet via peer-list poisoning, sinkholing, and domain seizures
On August 31, 2026, US and European authorities working with CrowdStrike and the Shadowserver Foundation sinkholed the Sality P2P botnet, active since 2003, isolating 15,000+ infected machines in the operation; the botnet is linked to over 11 million unique…
An international operation executed on August 31, 2026 disrupted Sality, a Russia-based (per CyberScoop) peer-to-peer botnet active since 2003. The US Justice Department, FBI, and DoD Office of Inspector General's Defense Criminal Investigative Service seized Sality-linked domains, with parallel police action in Bulgaria, Hungary, and Romania and support from Europol; the botnet operators were not named. The disruption targeted Sality's decentralized super-peer architecture: CrowdStrike poisoned the bots' super-peer lists via protocol-level manipulation that exploited the network's reputation mechanism, inserting sinkhole entries into emptied peer lists so infected machines permanently disappeared from the operator's view, making the botnet irrecoverable. The Register reports more than 15,000 infected machines were isolated and diverted into sinkholes; CyberScoop reports the botnet infected over 11 million devices over its lifetime, and Infosecurity Magazine reports it peaked at more than one million infected machines with over 11 million unique IP addresses linked to its infrastructure since 2017. Sality distributed credential theft, spam, proxy, and DDoS payloads — Europol attributed three DDoS attacks to it — and for eight years its primary payload was EggJagger, a clipboard hijacker that swaps copied bitcoin and ethereum wallet addresses with attacker-controlled ones, yielding at least $150,000 in stolen cryptocurrency. Europol said the effort dates back to 2017. The Shadowserver Foundation is coordinating with ISPs and CSIRTs to identify infections, notify victims, and support remediation.
- Sality is a peer-to-peer botnet active since 2003 (a roughly 23-year run; Infosecurity describes it as 20+ years), reported by CyberScoop as Russia-based; operators not named.
- The disruption operation took place on August 31, 2026 (Infosecurity Magazine; the other reports give no exact date).
- Participants: US DOJ, FBI, and DoD OIG's Defense Criminal Investigative Service (domain seizures); police in Bulgaria, Hungary, and Romania; Europol support; CrowdStrike and the Shadowserver Foundation on the technical side.
- Method: poisoned the bots' super-peer lists using protocol-level manipulation that exploited the super-peer reputation mechanism, inserted sinkhole entries into emptied peer lists, and severed infected peers so the botnet became…
- Scale: The Register reports 15,000+ infected machines isolated in the operation; CyberScoop reports over 11 million infected devices over the botnet's lifetime; Infosecurity reports a peak of more than 1 million infected machines and over…
- Payloads: credential theft, spam, proxy services, and DDoS; Europol attributed three DDoS attacks to the botnet.
- For eight years Sality's primary payload was EggJagger, a clipboard hijacker that swaps copied bitcoin and ethereum wallet addresses with attacker-controlled ones, stealing at least $150,000 in cryptocurrency (The Register only).
- Europol said the takedown effort dates back to 2017.
Coverage timelineoldest first · each row is one article
- · 15d agoCops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes
The Register · Security· 72
Law enforcement and CrowdStrike disrupted the 23-year-old Sality P2P botnet, isolating 15,000+ infected machines and seizing linked domains.