23-Year-Old Sality P2P Botnet Disrupted
23-year-old Sality P2P botnet disrupted by international law enforcement effort.
Summary
An international law enforcement operation, involving CrowdStrike and multiple countries, has successfully disrupted the Sality peer-to-peer (P2P) botnet, which had been active for 23 years. The operation involved manipulating the botnet's peer list and taking down URLs hosting its payloads, effectively isolating infected machines and preventing new infections. Sality was known for distributing various malware, including the EggJagger clipjacking tool, which allegedly stole over $150,000 in cryptocurrency.
Full text
After 23 years of operation, the Sality peer-to-peer (P2P) botnet has been disrupted as part of an international law enforcement effort. First observed in 2003, Sality has been used for distributing various malware families, including information stealers, proxy services, distributed denial-of-service (DDoS) payloads, and more. For the past eight years, it mainly served the EggJagger clipjacking tool, which is believed to have stolen at least $150,000 in Bitcoin and Ethereum. Sality remained active due to its architecture: it spread through a file infector, attaching itself to executables on disk and removable media, and did not rely on a central command-and-control (C&C) server for receiving code updates. The protocol behavior that allowed the botnet to persist for over 20 years was also the weakness that led to its demise: it blindly trusted the peers on the network, without authentication or identity verification. Sality bots periodically checked if the peers in their list of super peers (infected machines forming the backbone of the P2P network) were accessible. Those that were online built reputation, while those offline lost it and were eventually purged.Advertisement. Scroll to continue reading. Exploiting this behavior, CrowdStrike performed protocol-level manipulation of the list, removing the super peer entries to progressively isolate infected machines, while injecting sinkholes into the list. Coordinating with CrowdStrike’s bot isolation and P2P network sinkholing, law enforcement in the US, Bulgaria, Hungary, and Romania took down the URLs hosting Sality payloads, ensuring that the infected machines would not receive new payloads. “The criminal behind Sality has lost the ability to communicate with infected machines. The disruption operation isolates all peers in the network from their control. […] All Sality-infected machines now beacon to CrowdStrike-operated sinkholes,” CrowdStrike notes. As part of the disruption effort, The Shadowserver Foundation is working with ISPs and CSIRTs to identify botnet victims and clean up the infections. Related: Five Venezuelans Plead Guilty in US Court to ATM Jackpotting Related: US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks Related: Pro-Russian Hackers Claim Responsibility for Major Cyberattack on Norway’s Public Digital Services Related: Google, FBI Disrupt NetNut Residential Proxy Network Powered by Millions of Devices Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Ransomware Gang Claims Nutex Health Data Breach9.5 Million Impacted by Aesto Health Data BreachWatchGuard Patches Critical VulnerabilitiesServiceNow Patches 3 Critical Code Injection VulnerabilitiesMcKesson Confirms Data Breach as Attacker Deadline LoomsCritical Ruby on Rails Vulnerability in Attackers’ CrosshairsExtortion Group Claims Manchester Airports Group Data BreachBerlin Won’t Pay Extortion Group Claiming Data Theft Latest News Chrome and Firefox Updates Patch Dozens of VulnerabilitiesSonicWall Warns of Two SMA1000 Zero-Days Exploited in AttacksPalo Alto Networks Acquires AI Agent Platform ConsoleSevii Targets AI-Speed Attacks With Preemptive Autonomous DefenseCoast Guard Establishes Office of Maritime Cybersecurity PolicyExperiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of DollarsHackers Start Exploiting Critical Langflow VulnerabilityFive Venezuelans Plead Guilty in US Court to ATM Jackpotting Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveSectigo has named Ian Hassard as Chief Product Officer.Australian Securities Exchange has appointed Hanlie Botha as Deputy Chief Information Security Officer.Social engineering protection company Doppel has promoted Alyssa Smrekar to Chief Marketing Officer.More People On The MoveExpert Insights What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Flipboard Reddit Whatsapp Whatsapp Email