Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Sality P2P Botnet Dismantled After Decades

Sality P2P Botnet Dismantled After Decades

Posted on September 2, 2026 By CWS

In a significant victory for cybersecurity, the Sality peer-to-peer (P2P) botnet, which has been operational for 23 years, has been effectively dismantled. This takedown was part of an extensive international law enforcement operation.

History and Impact of Sality

First identified in 2003, the Sality botnet has been a versatile tool for cybercriminals. It has facilitated the distribution of numerous malware families, including information-stealing software, proxy services, and distributed denial-of-service (DDoS) attacks.

In recent years, Sality primarily supported the EggJagger clipjacking tool, which is suspected of stealing over $150,000 in Bitcoin and Ethereum. The botnet’s persistence was largely due to its unique architecture that allowed it to spread via file infection, attaching itself to executable files on both hard drives and removable media.

Technical Vulnerabilities and Exploitation

Despite its longevity, the same protocol behaviors that allowed Sality to thrive eventually led to its downfall. The botnet’s P2P network operated without any form of authentication, trusting all connected peers blindly. This lack of security measures proved to be a critical vulnerability.

CrowdStrike, a cybersecurity firm, exploited this weakness by manipulating the network protocol. They removed entries of super peers, the infected machines forming the network’s core, and inserted sinkholes to isolate these machines progressively.

Coordinated Takedown Effort

In collaboration with law enforcement agencies across the US, Bulgaria, Hungary, and Romania, CrowdStrike’s efforts were amplified to dismantle the botnet thoroughly. These agencies targeted and deactivated URLs distributing Sality’s malicious payloads, preventing further infections.

As a result, the cybercriminals behind Sality lost all communication with the infected machines, which now only connect to CrowdStrike-managed sinkholes. The Shadowserver Foundation is also aiding in this effort by partnering with ISPs and CSIRTs to identify and clean up affected systems.

This operation marks a pivotal moment in the fight against cybercrime, highlighting the importance of international cooperation and innovative cybersecurity strategies.

Security Week News Tags:botnet disruption, CrowdStrike, Cybercrime, Cybersecurity, law enforcement, Malware, network security, P2P botnet, Sality, Shadowserver Foundation

Post navigation

Previous Post: Russian Hacker Extradited for Major Excel Malware Attack
Next Post: HPE Fabric Composer Vulnerabilities Expose Critical Security Risks

Related Posts

Sophisticated Phishing Attack Targets Security Firm Executive Sophisticated Phishing Attack Targets Security Firm Executive Security Week News
Microsoft Patches 130 Vulnerabilities for July 2025 Patch Tuesday Microsoft Patches 130 Vulnerabilities for July 2025 Patch Tuesday Security Week News
Russian Government Hackers Caught Buying Passwords from Cybercriminals Russian Government Hackers Caught Buying Passwords from Cybercriminals Security Week News
Zyxel Firewall Vulnerability Again in Attacker Crosshairs Zyxel Firewall Vulnerability Again in Attacker Crosshairs Security Week News
SolarWinds Web Help Desk Vulnerabilities Exploited in Attacks SolarWinds Web Help Desk Vulnerabilities Exploited in Attacks Security Week News
Victoria’s Secret Says It Will Postpone Earnings Report After Recent Security Breach Victoria’s Secret Says It Will Postpone Earnings Report After Recent Security Breach Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CenterPoint Energy Reports Customer Data Breach Incident
  • Hackuity Secures $19M to Boost AI Vulnerability Management
  • Browser Extension Risks AI Assistant Security
  • Urgent Patch for Major Check Point Vulnerability Released
  • Google Fixes Pixel Zero-Day Vulnerability Amid Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CenterPoint Energy Reports Customer Data Breach Incident
  • Hackuity Secures $19M to Boost AI Vulnerability Management
  • Browser Extension Risks AI Assistant Security
  • Urgent Patch for Major Check Point Vulnerability Released
  • Google Fixes Pixel Zero-Day Vulnerability Amid Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark