Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads
Authorities successfully dismantled a long-standing peer-to-peer botnet, Sality, through a coordinated international operation. By turning the botnet's own P2P architecture against itself, they effectively neutralized its ability to spread new malware and steal cryptocurrency. The operation involved sinkholing P2P networks and URLs hosting Sality payloads, and now existing infections are being addressed. This highlights that even resilient criminal infrastructure can be disrupted with strategic technical investment and collaboration.
The U.S. Department of Justice, in collaboration with authorities from Bulgaria, Hungary, and Romania, alongside private industry partners CrowdStrike and the Shadowserver Foundation, announced the takedown of a long-standing peer-to-peer (P2P) botnet, Sality, on August 31, 2026. To achieve this, a peer-to-peer sinkhole operation was carried out to eliminate the threat. Simultaneously, Sality-linked domains have been seized in the U.S. and Europe.
Sality has been documented in the wild since 2003, capable of infecting and modifying Windows executable files and spreading additional malicious software for credential theft, spam distribution, proxy services, network exploitation, and distributed denial-of-service (DDoS) attacks. Over the years, several variants of the Windows malware have been equipped with the ability to communicate over a P2P network, bypassing traditional command-and-control (C2) server shutdown tactics. One of the primary payloads delivered via Sality is EggJagger, a clipper tool that continuously monitors a device's clipboard for cryptocurrency wallet addresses and stealthily substitutes them with threat actor-controlled ones to redirect transactions, resulting in an estimated $150,000 in stolen funds.
Sality has been used in several notable DDoS attack campaigns, including targeting the Arabic Financial Forum (“forex2030[.]com”) in April 2016, Ukrainian Forum (“kharkovforum[.]com”) in February 2022 (following Russia’s invasion of Ukraine), and AvanChange in September 2023. The malware has been distributed through various methods, including infected network shares, USB devices, file sharing, compromised websites, email attachments, and P2P networks, creating a self-propagating botnet.
In July 2022, Dragos revealed a campaign targeting industrial engineers and operators to seize control of Programmable Logic Controllers (PLCs) and co-opt them into the Sality botnet. The botnet allowed the operator to distribute malicious payloads to over 15,000 infected machines worldwide, with two independent P2P networks, version 3 and version 4, remaining active until the disruption. These networks shared the same codebase and were operated by the same threat actor, but used incompatible protocol versions and different cryptographic keys.
The takedown operation involved turning Sality’s P2P architecture against itself by manipulating the peer list, a data structure containing a finite set of known super peers. The botnet checks whether its stored peers are still online every 40 minutes, purging peers that fail to respond. This maintenance cycle is abused to remove legitimate peers via protocol-level manipulation during peer verification and insert purpose-built sinkhole entries into the emptied peer list. The operation also involved sinkholing the URLs hosting Sality payloads, including:
- theunforgiven.p8[.]hu/img/top.gif
- painelwebradiodigital.awardspace[.]info/v3/readme.pdf
- sgwebdesigner.free[.]fr/left.gif
- www.yonelco[.]com/icon.png
- pozdravizbeograda[.]com/readme.pdf
- highclass.atspace[.]com/styles.gif
- situluimihai.3x[.]ro/top.png
- gatheredovertime[.]com/nb4
- imagebucket[.]biz/nv4
Existing malware installed on infected machines remains active and should be removed. The dismantling of Sality is a key component of President Donald Trump’s Cyber Strategy for America, referred to as “Shape Adversary Behavior,” aiming to identify and disrupt malicious networks and alter adversary calculus by degrading their tools and infrastructure. The FBI, in collaboration with international law enforcement and private sector partners, will continue to work to prevent further cyber-enabled attacks and theft from victims in the United States.
