Sality P2P botnet infrastructure disrupted in joint global takedown
BleepingComputer and SecurityWeek report a 2 September 2026 joint disruption of the long-running Sality peer-to-peer botnet. Europol, Eurojust, the U.S. DOJ, FBI and DCIS seized Sality-linked domains in the United States, with further seizures in Bulgaria, Hungary and Romania. CrowdStrike's Counter Adversary Operations, with law-enforcement and industry partners, sinkholed known super-peer lists that form the botnet's communication backbone, blocking file packs and URL packs that push payloads. CrowdStrike says Sality has been active since at least 2003, has infected more than 15,000 devices historically, and that the two still-active networks at takedown were mainly used to push EggJagger clipjacking payloads; earlier payload history spans credential theft, spam, proxies, exploitation and DDoS. BC quotes CrowdStrike that after more than two decades the botnet is now no longer able to push new malware payloads through those channels.
- Product
- Sality botnet
- Exploited in Australia?
- unknown
Primary: BleepingComputer ยท SecurityWeek
