Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Authorities Dismantle Sality Botnet, Halting Malware Spread

Authorities Dismantle Sality Botnet, Halting Malware Spread

Posted on September 2, 2026 By CWS

The U.S. Department of Justice (DoJ) has successfully dismantled the notorious Sality botnet, a significant peer-to-peer (P2P) network, in a coordinated international effort. This operation, conducted on August 31, 2026, involved authorities from the U.S., Bulgaria, Hungary, and Romania, alongside private partners like CrowdStrike and the Shadowserver Foundation. The initiative included a P2P sinkhole operation and the seizure of Sality-associated domains in the U.S. and Europe.

Details of the Sality Botnet

Sality has been a persistent threat since its emergence in 2003, notorious for infecting Windows executable files and deploying additional malware for various malicious activities. These activities include credential theft, spam distribution, proxy services, network exploitation, and distributed denial-of-service (DDoS) attacks. The botnet is believed to be operated by a group known as Salty Spider, originating from the Republic of Bashkortostan in Russia.

Over the years, Sality evolved with variants capable of communicating over a P2P network, circumventing traditional command-and-control server shutdowns. A notable payload delivered by Sality is EggJagger, a tool that alters clipboard cryptocurrency wallet addresses to redirect transactions, amassing approximately $150,000 for the threat actors.

Operation and Techniques Utilized

The takedown operation ingeniously turned Sality’s P2P architecture against itself, isolating network peers from the threat actor’s control. This effectively halted their ability to communicate with infected machines, preventing further payload downloads or transfers. The operation leveraged a technique called peer list manipulation, previously used in dismantling the GameOver Zeus and Kelihos botnets.

By exploiting Sality’s P2P protocol vulnerabilities, the operation removed legitimate peers from the network and inserted purpose-built sinkhole entries, isolating super peers and disrupting the botnet’s communication backbone. As a result, both URL and file packs ceased to propagate, effectively neutralizing the majority of infections.

Impact and Future Outlook

The coordinated effort not only sinkholed the P2P network but also eliminated URLs hosting Sality payloads, preventing the malware from downloading additional files. All Sality-infected machines now report to CrowdStrike-operated sinkholes, and organizations are advised to review network logs for UDP traffic to the specific “lighthouse” IP address, indicating potential infections.

This operation highlights the vulnerability of P2P architectures previously considered resilient. It underscores the importance of collaboration between law enforcement and private entities in dismantling cybercriminal infrastructure. While the disruption stops new payloads, existing malware on infected systems remains active and requires removal.

The joint effort aligns with President Donald Trump’s Cyber Strategy for America, focusing on identifying and disrupting malicious networks. The FBI, alongside international partners, continues to enhance cybersecurity capabilities and mitigate the threat posed by such botnets, ensuring the protection of victims in the United States.

The Hacker News Tags:Botnet, CrowdStrike, Cybercrime, Cybersecurity, DoJ, law enforcement, Malware, P2P network, Sality, Shadowserver Foundation

Post navigation

Previous Post: GitSpawn Vulnerabilities Risk AI Coding Agents
Next Post: WhatsApp Flaw Exposes Android Photos via Video Call

Related Posts

Unveiling Cyber Deception: Lessons from Art Forgery Unveiling Cyber Deception: Lessons from Art Forgery The Hacker News
Google Chrome to Distrust Two Certificate Authorities Over Compliance and Conduct Issues Google Chrome to Distrust Two Certificate Authorities Over Compliance and Conduct Issues The Hacker News
New Investment Scams Use Facebook Ads, RDGA Domains, and IP Checks to Filter Victims New Investment Scams Use Facebook Ads, RDGA Domains, and IP Checks to Filter Victims The Hacker News
Microsoft 365 Android Apps Vulnerability Allows Token Theft Microsoft 365 Android Apps Vulnerability Allows Token Theft The Hacker News
Researchers Warn of MystRodX Backdoor Using DNS and ICMP Triggers for Stealthy Control Researchers Warn of MystRodX Backdoor Using DNS and ICMP Triggers for Stealthy Control The Hacker News
Silver Fox Intensifies Asia Cyber Campaign with New Trojan Silver Fox Intensifies Asia Cyber Campaign with New Trojan The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • WhatsApp Flaw Exposes Android Photos via Video Call
  • Authorities Dismantle Sality Botnet, Halting Malware Spread
  • GitSpawn Vulnerabilities Risk AI Coding Agents
  • OpenLeash Enhances AI Security with Human Oversight
  • Google and Rivals Launch Advanced Cybersecurity AI Models

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • WhatsApp Flaw Exposes Android Photos via Video Call
  • Authorities Dismantle Sality Botnet, Halting Malware Spread
  • GitSpawn Vulnerabilities Risk AI Coding Agents
  • OpenLeash Enhances AI Security with Human Oversight
  • Google and Rivals Launch Advanced Cybersecurity AI Models

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark