Sality P2P botnet crippled in global law crackdown

US and European authorities, working with private-sector partners, have disrupted the long-running Sality peer-to-peer botnet in a global operation that severed its ability to deliver new malware payloads.[2][5][8] The takedown, executed on Aug. 31, 2026, combined law-enforcement domain seizures with a technical sinkhole that turned Sality’s decentralized network against itself by cutting infected hosts off from the attackers’ command channel.[1][2][12]

Sality is one of the internet’s oldest active botnets, with researchers estimating it has been operating for roughly two decades as part of a Russia-based cybercrime ecosystem.[1][5][7] The malware uses a modular architecture and a resilient P2P protocol to spread across Windows systems, harvest credentials, deploy additional payloads and abuse infected machines for spam, distributed denial-of-service attacks and cryptocurrency theft.[1][6][8]

In the latest operation, CrowdStrike’s Counter Adversary Operations team and the Shadowserver Foundation worked alongside investigators in the United States, Bulgaria, Hungary and Romania to poison Sality’s peer lists, isolating high-value nodes first and then propagating corrective data through the network.[1][4][15] Authorities also seized Sality-linked domains in the US and Europe, further disrupting the infrastructure used to stage payloads and coordinate infected hosts.[2][4][5] Current estimates cited by law-enforcement partners put the actively controlled portion of the botnet at more than 15,000 compromised machines worldwide, though historical infection numbers are believed to be significantly higher.[6][15]

While the sinkhole and domain seizures have cut off Sality’s operators from their existing fleet, many endpoints still remain infected and will continue attempting to communicate with now-neutralized peers.[1][6][8] Officials and researchers warn that the criminal group behind Sality could attempt to rebuild the operation using surviving malware components or by repurposing parts of the P2P protocol for new infrastructure.[1][5][6]

Over its lifespan Sality has been linked to the exploitation of multiple vulnerabilities, including the Windows shortcut flaw tracked as CVE-2010-2568 and an industrial control system weakness in AutomationDirect DirectLOGIC CPUs tracked as CVE-2022-2003.[10][13] Researchers at Dragos and other firms have reported that CVE-2022-2003, disclosed in 2022, was used in conjunction with tainted password-cracking tools, and that AutomationDirect issued firmware updates to mitigate the issue.[10][13] Defenders are urged to ensure systems are patched against known Sality-linked vulnerabilities, scan for and remove Sality binaries from endpoints, clear residual scheduled tasks and autorun entries, and monitor for any attempts to revive P2P communications on their networks.[1][8][10]

References

  1. Peer Pressure: Inside the Sality Botnet Disruption Operation
  2. Authorities Turn Sality’s P2P Network Against Itself, Cutting …
  3. US-Behörden zerstören Sality per P2P-Sinkhole: Botnet verliert neue Payloads
  4. Russian cybercrime operation being dismantled after two …
  5. Security Week Home
  6. ロシアのサイバー犯罪網解体へ、20年間活動 米当局とクラウド …
  7. BleepingComputer | Cybersecurity, Technology News and …
  8. Sality – Mallory.ai
  9. DOJ und Partner kappen Sality-P2P-Botnet durch Sinkholing und Peer-Listen-Manipulation
  10. Tainted password-cracking software used to spread P2P Sality bot
  11. Cops, CrowdStrike disrupt Sality botnet by poisoning …

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply