The U.S. Department of Justice (DoJ) has successfully dismantled the notorious Sality botnet, a significant peer-to-peer (P2P) network, in a coordinated international effort. This operation, conducted on August 31, 2026, involved authorities from the U.S., Bulgaria, Hungary, and Romania, alongside private partners like CrowdStrike and the Shadowserver Foundation. The initiative included a P2P sinkhole operation and the seizure of Sality-associated domains in the U.S. and Europe.
Details of the Sality Botnet
Sality has been a persistent threat since its emergence in 2003, notorious for infecting Windows executable files and deploying additional malware for various malicious activities. These activities include credential theft, spam distribution, proxy services, network exploitation, and distributed denial-of-service (DDoS) attacks. The botnet is believed to be operated by a group known as Salty Spider, originating from the Republic of Bashkortostan in Russia.
Over the years, Sality evolved with variants capable of communicating over a P2P network, circumventing traditional command-and-control server shutdowns. A notable payload delivered by Sality is EggJagger, a tool that alters clipboard cryptocurrency wallet addresses to redirect transactions, amassing approximately $150,000 for the threat actors.
Operation and Techniques Utilized
The takedown operation ingeniously turned Sality’s P2P architecture against itself, isolating network peers from the threat actor’s control. This effectively halted their ability to communicate with infected machines, preventing further payload downloads or transfers. The operation leveraged a technique called peer list manipulation, previously used in dismantling the GameOver Zeus and Kelihos botnets.
By exploiting Sality’s P2P protocol vulnerabilities, the operation removed legitimate peers from the network and inserted purpose-built sinkhole entries, isolating super peers and disrupting the botnet’s communication backbone. As a result, both URL and file packs ceased to propagate, effectively neutralizing the majority of infections.
Impact and Future Outlook
The coordinated effort not only sinkholed the P2P network but also eliminated URLs hosting Sality payloads, preventing the malware from downloading additional files. All Sality-infected machines now report to CrowdStrike-operated sinkholes, and organizations are advised to review network logs for UDP traffic to the specific “lighthouse” IP address, indicating potential infections.
This operation highlights the vulnerability of P2P architectures previously considered resilient. It underscores the importance of collaboration between law enforcement and private entities in dismantling cybercriminal infrastructure. While the disruption stops new payloads, existing malware on infected systems remains active and requires removal.
The joint effort aligns with President Donald Trump’s Cyber Strategy for America, focusing on identifying and disrupting malicious networks. The FBI, alongside international partners, continues to enhance cybersecurity capabilities and mitigate the threat posed by such botnets, ensuring the protection of victims in the United States.
