Peer Pressure: Inside the Sality Botnet Disruption Operation
Cybersecurity Classified by Officially
CrowdStrike collaborated with international law enforcement and industry partners to execute a coordinated disruption of the Sality peer-to-peer botnet.
On August 31, 2026, CrowdStrike's Counter Adversary Operations team, in collaboration with international law enforcement and industry partners, executed a coordinated disruption of the Sality peer-to-peer (P2P) botnet, a criminal infrastructure that has operated with seeming impunity for more than two decades.
The botnet enabled the operator to distribute malicious payloads to over 33,000 infected machines worldwide. We executed a peer-to-peer sinkholing operation that isolates infected machines, rendering the criminal's command channel inert.
This action was carried out in partnership with the U.S. Department of Justice (DOJ), the Federal Bureau of Investigation (FBI), the Department of Defense Office of Inspector General’s Defense Criminal Investigative Service (DCIS), and the Shadowserver Foundation, with support from Europol, Eurojust, and law enforcement agencies in Bulgaria, Hungary, and Romania. We also acknowledge additional unnamed partners whose contributions were essential to the success of this operation.
Active disruption of criminal infrastructure is a necessary component of a modern response to cyber threats. CrowdStrike is committed to taking the fight to the adversaries, regardless of how long they have operated or how resilient their infrastructure appears.
Sality is a file-infecting malware that evolved from a traditional botnet into a sophisticated P2P botnet over its more-than-20-year lifespan. First observed in 2003, it has been one of the most persistent threats on the internet, not because of its payloads but because of the robustness of its architecture.
Two independent P2P networks, known as version 3 and version 4, remained active until this week. They shared the same codebase and were operated by the same threat actor, but used incompatible protocol versions and different cryptographic keys.
This is an extract. The publication continues at the source.
Read the original at the source: https://www.crowdstrike.com/en-us/blog/inside-sality-botnet-disruption-operation/
Officially imported this from CrowdStrike’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- CrowdStrike — imported from official source
- Official source
- https://www.crowdstrike.com/blog/feed/ RSS
- Imported
- September 18, 2026 11:35
- Versions
- 1 recorded
- Identity
https://www.crowdstrike.com/?p=404871