International operation dismantles Russia-based Sality P2P botnet after two-decade run
On August 31, 2026, law enforcement from the US, Bulgaria, Hungary and Romania, with Europol, CrowdStrike and the Shadowserver Foundation, disrupted the Russia-based Sality peer-to-peer botnet by seizing domains and manipulating its peer-list mechanism;…
A coordinated international operation on August 31, 2026 disrupted the Sality peer-to-peer botnet. Participants included US authorities — identified by CyberScoop as the FBI and Justice Department — Europol, and authorities from Bulgaria, Hungary and Romania, supported by private-sector partners CrowdStrike and the Shadowserver Foundation. The takedown seized the botnet's domains and sinkholed its communications. The two sources differ on the botnet's age: CyberScoop calls it a 23-year run, while Infosecurity Magazine says it operated for over 20 years. They also frame its scale differently: CyberScoop says it infected more than 11 million devices, while Infosecurity Magazine says it peaked at more than one million infected machines and that over 11 million unique IP addresses have been linked to its infrastructure since 2017. The financially motivated botnet was used for cryptocurrency theft, DDoS attacks, credential theft, spam and proxy services; CyberScoop additionally reports three DDoS attacks attributed to it. The disruption targeted the botnet's decentralized P2P design, which had let it evade disruption for over two decades: CrowdStrike poisoned the peer list via protocol-level manipulation of its super-peer reputation mechanism, so infected machines permanently disappeared from the operator's view — making the botnet irrecoverable per CyberScoop — and sinkhole entries were inserted into the emptied peer lists. Europol said the effort dates back to 2017. The operators were not named, and Shadowserver is coordinating with ISPs and CSIRTs to identify, notify and remediate infected devices.
- Disruption operation carried out on August 31, 2026
- Participants: US authorities (FBI and Justice Department, per CyberScoop), Europol, and authorities from Bulgaria, Hungary and Romania, plus CrowdStrike and the Shadowserver Foundation
- Target: Sality, a Russia-based peer-to-peer botnet
- Age discrepancy: 23 years (CyberScoop) vs. over 20 years (Infosecurity Magazine)
- Scale discrepancy: more than 11 million infected devices (CyberScoop) vs. peak of more than one million infected machines and over 11 million unique IP addresses linked since 2017 (Infosecurity Magazine)
- Botnet uses: cryptocurrency theft, DDoS attacks (both sources), plus credential theft, spam and proxy services (Infosecurity Magazine)
- Three DDoS attacks were attributed to the botnet alongside its criminal use (CyberScoop)
- Method: domain seizures plus sinkholing; CrowdStrike poisoned the peer list via protocol-level manipulation of the super-peer reputation mechanism, permanently hiding infected machines from the operator and rendering the botnet…
Coverage timelineoldest first · each row is one article
- · 13d agoDogged Russia-based botnet dismantled after 23-year run
CyberScoop· 72
Law enforcement, CrowdStrike and Shadowserver dismantled the 23-year-old Sality P2P botnet that infected more than 11 million devices.