Skip to content
The Cybersecurity Focus
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
BotNetWorld

International Law Enforcement Dismantles Sality Botnet

By ogwatermelon
September 2, 2026 5 Min Read
0

International law enforcement agencies and private cybersecurity partners have seized infrastructure associated with the Sality botnet, one of the longest-running peer-to-peer (P2P) botnets in cybercrime history. The coordinated operation, carried out on August 31, 2026, involved authorities from the United States, Bulgaria, Hungary, and Romania, working alongside CrowdStrike and the Shadowserver Foundation. The takedown marks the end of a malware operation that has plagued Windows systems since 2003, infecting more than 15,000 devices worldwide and distributing payloads ranging from credential-stealing trojans to cryptocurrency clipjacking tools.

What Happened: Sality Botnet Dismantled After 20+ Years of Operation

The Sality botnet, operated by a threat actor tracked as SALTY SPIDER and believed to be based in the Republic of Bashkortostan, Russia, was successfully disrupted on August 31, 2026. The U.S. Department of Justice (DoJ), FBI, and DCIS seized Sality-linked domains in the United States, while Bulgarian, Hungarian, and Romanian authorities seized additional domains hosted in Europe. The operation was coordinated through Europol and Eurojust. CrowdStrike’s Counter Adversary Operations team simultaneously conducted a peer-to-peer sinkhole operation that isolated infected machines and severed the botnet’s command-and-control capabilities. Sality’s P2P architecture, which had made the botnet resilient against traditional C2 takedowns, was turned against itself through a technique called peer list manipulation.

Two independent Sality P2P networks, known as version 3 and version 4, remained active until the disruption. These networks shared the same codebase and were operated by the same threat actor but used incompatible protocol versions and different cryptographic keys. The botnet primarily distributed EggJagger, a clipjacking tool that monitors the clipboard for cryptocurrency wallet addresses and silently replaces them with addresses controlled by the attacker. CrowdStrike estimates the operators stole at least $150,000 through this method.

Technical Details of the Sality Botnet Takedown

Sality is a Windows-based malware family that has evolved continuously since 2003. Its core capabilities include infecting and modifying Windows executable files, self-propagating through infected network shares, USB devices, file-sharing networks, and email attachments. The malware communicates over a P2P network rather than a traditional client-server C2 model, allowing it to survive the shutdown of individual C2 servers by using infected machines as peer nodes.

The takedown leveraged a technique known as peer list manipulation, also used in the 2014 GameOver Zeus and 2017 Kelihos botnet disruptions. Sality’s P2P protocol blindly trusts any machine that correctly responds to the peer handshake, with no authentication or cryptographic identity verification. The operation exploited this by inserting sinkhole entries into the botnet’s peer list during its routine peer verification cycle, which runs every 40 minutes. Peers that fail verification lose reputation and are eventually purged, allowing the sinkhole nodes to gradually isolate infected machines.

The disruption targeted super peers first, as they form the network’s communication backbone. Once isolated, both URL packs (payload download instructions) and file packs (direct payload transfers) stopped propagating. For machines behind firewalls or NAT that could not be directly contacted, the sinkhole nodes purges their peer lists passively when those machines checked in during routine maintenance cycles, permanently isolating them from operator control.

Seized Sality payload distribution domains include:

  • theunforgiven.p8[.]hu/img/top.gif
  • painelwebradiodigital.awardspace[.]info/v3/readme.pdf
  • sgwebdesigner.free[.]fr/left.gif
  • www.yonelco[.]com/icon.png
  • pozdravizbeograda[.]com/readme.pdf
  • highclass.atspace[.]com/styles.gif
  • situluimihai.3x[.]ro/top.png
  • gatheredovertime[.]com/nb4
  • imagebucket[.]biz/nv4

All Sality-infected machines are now configured to beacon to CrowdStrike-operated sinkholes. The sinkhole IP address is 188.166.101[.]148.

Business and Operational Impact

The Sality takedown eliminates a significant distributed cybercrime infrastructure that has generated illicit revenue for over two decades. The following impacts are noteworthy:

  • Infected Machine Count: More than 15,000 devices worldwide were confirmed as part of the Sality botnet, spanning multiple versions and P2P networks.
  • Financial Impact: EggJagger clipjacking operations are estimated to have stolen at least $150,000 by swapping cryptocurrency wallet addresses in user clipboards.
  • Payload Diversity: Sality distributed malware spanning credential theft, spam distribution, proxy services, network exploitation, DDoS attacks, and clipjacking — indicating a broad criminal business model.
  • DDoS Campaigns: The botnet was repurposed for at least three notable DDoS attacks: the Arabic Financial Forum in April 2016, the Ukrainian Forum (kharkovforum[.]com) in February 2022 following Russia’s full-scale invasion of Ukraine, and AvanChange in September 2023.
  • Industrial Control Systems: In July 2022, Dragos revealed a campaign targeting industrial engineers and operators to seize control of PLCs and co-opt devices into the Sality botnet, raising concerns about critical infrastructure exposure.
  • International Scope: The takedown required coordination across four countries and two private industry partners, demonstrating the complexity and cost of dismantling mature cybercrime operations.

Mitigation and Recommendations

Organizations with Windows infrastructure should take the following steps to detect and remediate Sality infections, and to defend against similar P2P botnet threats.

Detecting Sality Infections

  1. Review network logs and endpoint telemetry for UDP traffic to the sinkhole IP address 188.166.101[.]148. Any such traffic indicates a Sality infection requiring immediate remediation.
  2. Check for suspicious entries in /var/log/switchvox/db-quirks.log on affected VoIP systems (note: this applies specifically to Sangoma Switchvox environments; Sality primarily targets Windows endpoints).
  3. Monitor for executable files that have been modified or replaced, particularly in shared network locations and on systems with USB device exposure.
  4. Look for unusual outbound UDP traffic on non-standard ports, which may indicate P2P botnet communication.

Remediating Infected Systems

  1. Isolate confirmed infected machines from the network immediately to prevent further propagation or communication with sinkhole infrastructure.
  2. Reimage Windows endpoints rather than attempting to clean malware in place, as Sality’s file-infection capability makes manual removal unreliable.
  3. Reset credentials on compromised systems, particularly those used for administrative access, as Sality has historically deployed credential-stealing modules.
  4. Notify users whose machines were infected, as their clipboard data and potentially stored credentials may have been exposed.

Defending Against P2P Botnets

  1. Deploy endpoint detection and response (EDR) solutions capable of identifying anomalous P2P network behavior and file-infection patterns.
  2. Restrict executable file execution from user-writable directories and network shares where possible.
  3. Implement application whitelisting to prevent unauthorized executables from running, particularly on servers and critical workstations.
  4. Monitor for DNS queries to newly registered or suspicious domains, which may indicate malware attempting to contact C2 or P2P infrastructure.

Bottom line: The Sality takedown demonstrates that even mature, P2P-based cybercrime operations can be dismantled through coordinated international law enforcement and precise technical operations. Organizations should treat this as an opportunity to hunt for residual infections, block the sinkhole IP in network monitoring tools, and ensure endpoint protections are configured to detect file-infection and P2P communication patterns.

Incident Summary

Incident: Sality Botnet Takedown — International Law Enforcement Operation
Date: August 31, 2026 (disruption); September 2, 2026 (public announcement)
Threat Actor: SALTY SPIDER (aka Kukacka, Sality, KuKu, SalLoad, Kookoo, SaliCode) — Republic of Bashkortostan, Russia
Affected Systems: Windows endpoints; 15,000+ confirmed infected machines globally
Key Malware: Sality (file infector and P2P botnet), EggJagger (clipjacking tool)
Law Enforcement: U.S. DoJ, FBI, DCIS, Bulgaria, Hungary, Romania; coordinated via Europol and Eurojust
Private Partners: CrowdStrike Counter Adversary Operations, Shadowserver Foundation
Sinkhole IP: 188.166.101[.]148
Patch Status: N/A — this is a law enforcement action, not a vulnerability patch. Remediation requires endpoint reimaging.

References

  1. U.S. Department of Justice, “CrowdStrike and International Law Enforcement Disrupt 20-Year-Old Sality Botnet,” DoJ Press Release, September 1, 2026, https://www.justice.gov/usao-cdca/pr/crowdstrike-and-international-law-enforcement-disrupt-20-year-old-sality-botnet, accessed September 2, 2026.
  2. BleepingComputer, “Sality botnet infrastructure dismantled in joint global takedown,” September 2, 2026, https://www.bleepingcomputer.com/news/security/sality-botnet-infrastructure-dismantled-in-joint-global-takedown/, accessed September 2, 2026.
  3. The Hacker News, “Authorities Turn Sality’s P2P Network Against Itself, Cutting Off New Malware Payloads,” September 2, 2026, https://thehackernews.com/2026/09/authorities-turn-salitys-p2p-network.html, accessed September 2, 2026.
  4. CrowdStrike, “Counter Adversary Operations: Sality Disruption,” CrowdStrike Blog, September 2, 2026, https://www.crowdstrike.com/blog/counter-adversary-operations-sality-disruption/, accessed September 2, 2026.
  5. Dragos, “Sality Campaign Targeting Industrial Control Systems,” Dragos Blog, July 2022, https://www.dragos.com/blog/industry-news/sality-campaign-targeting-industrial-control-systems, accessed September 2, 2026.

Tags:

BotnetWorld
Author

ogwatermelon

Follow Me
Other Articles
Previous

SonicWall SMA1000 Zero-Day Flaws Under Active Exploitation

Next

Sangoma Switchvox SQL Injection Under Active Exploitation

AI Botnet Breach CVE Exploit Hack Incident Infostealer Linux Mac Malware Network Phishing Ransomware RCE supply chain Vishing Vulnerability Windows World Zero Day

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026

Categories

  • AI
  • BotNet
  • Breach
  • CVE
  • exploit
  • Hack
  • Incident
  • Infostealer
  • Linux
  • Mac
  • Malware
  • Phishing
  • Ransomware
  • RCE
  • supply-chain
  • Uncategorized
  • Vishing
  • Vulnerability
  • Windows
  • World
  • Zero Day
Copyright 2026 — The Cybersecurity Focus. All rights reserved.