[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fhDEP2x3GQ_JkGlmSw8-PM0QUXhjx0jGRpQlq2Tc_WVM":3},{"article":4,"iocs":57},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":34,"category":35,"article_tags":39},"10faa14a-e8c7-47c7-965f-8668e735cc66","Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads","authorities-turn-sality-s-p2p-network-against-itself-cutting-off-new-malware-pay-81c96c","The U.S. Department of Justice (DoJ) on Tuesday announced the takedown of a long-standing peer-to-peer (P2P) botnet known as Sality as part of a coordinated law enforcement operation. The effort was undertaken on August 31, 2026, by authorities from the U.S., Bulgaria, Hungary, and Romania, in collaboration with private industry partners CrowdStrike and the Shadowserver Foundation. To that","A coordinated law enforcement operation involving the U.S. DoJ, Bulgaria, Hungary, and Romania, alongside CrowdStrike and Shadowserver Foundation, has successfully taken down the Sality peer-to-peer botnet. The operation utilized a sinkhole strategy to sever communication and seize Sality-linked domains, effectively neutralizing the malware's ability to distribute new payloads and infect machines worldwide. Sality, active since 2003, has been responsible for delivering various malicious software, including the cryptocurrency clipper EggJagger, and has been repurposed for DDoS attacks.","Authorities dismantled the Sality P2P botnet, disrupting malware distribution.","Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads Ravie LakshmananSep 02, 2026Malware \u002F Cybercrime The U.S. Department of Justice (DoJ) on Tuesday announced the takedown of a long-standing peer-to-peer (P2P) botnet known as Sality as part of a coordinated law enforcement operation. The effort was undertaken on August 31, 2026, by authorities from the U.S., Bulgaria, Hungary, and Romania, in collaboration with private industry partners CrowdStrike and the Shadowserver Foundation. To that end, a peer-to-peer sinkhole operation was carried out to eliminate the threat. In tandem, Sality-linked domains have been seized in the U.S. and Europe. \"Cybercriminals, botnets, and malware are a clear and present danger to our nation's security and economy,\" said First Assistant United States Attorney Bill Essayli. \"This successful effort to take down the Sality botnet shows that by working together, the public and private sectors can be a powerful force for good.\" Sality has been documented in the wild since 2003, featuring capabilities to infect and modify Windows executable files, and spread additional malicious software designed for credential theft, spam distribution, proxy services, network exploitation, and distributed denial-of-service (DDoS) attacks. Over the years, several variants of the Windows malware have been equipped with the ability to communicate over a P2P network, thereby allowing it to bypass traditional command-and-control (C2) server shutdown tactics. One of the primary payloads delivered via Sality is EggJagger, a clipper or clipjacking tool that continuously monitors a device's clipboard for cryptocurrency wallet addresses and stealthily substitutes them with threat actor-controlled ones to redirect transactions. It's estimated that the threat actors have stolen at least $150,000 using this method. Although Sality's operations are primarily driven by financial gain, the malware has been used to conduct three notable DDoS attack campaigns, highlighting the threat actor's willingness to repurpose the botnet for personal or political purposes, CrowdStrike said. The attacks targeted - Arabic Financial Forum (\"forex2030[.]com\") in April 2016 Ukrainian Forum (\"kharkovforum[.]com\") in February 2022, a day after Russia's full-scale invasion of Ukraine AvanChange in September 2023 It has been distributed through various methods, including infected network shares, USB devices, file sharing, compromised websites, email attachments, and peer-to-peer (P2P) networks, effectively creating a self-propagating botnet that regenerates new infections without requiring any active efforts from the threat actor. In July 2022, operational technology cybersecurity company Dragos revealed a campaign that targeted industrial engineers and operators to seize control of Programmable Logic Controllers (PLCs) and co-opt the devices into the Sality botnet. According to CrowdStrike, the botnet is said to have allowed the operator to distribute malicious payloads to more than 15,000 infected machines worldwide, adding that two independent P2P networks, known as version 3 and version 4, remained active until the disruption occurred. \"They shared the same codebase and were operated by the same threat actor, but used incompatible protocol versions and different cryptographic keys,\" the CrowdStrike Counter Adversary Operations said. The takedown operation involved turning Sality's P2P architecture against itself to isolate all peers in the network from the threat actor's control and neutralize their ability to communicate with infected machines. This, in turn, prevents them from receiving payload download instructions or payload transfers, rendering the botnet ineffective. \"The same properties that made Sality resilient also created the conditions for its undoing,\" CrowdStrike explained. \"Sality's P2P protocol cannot be patched. Unlike conventional malware that can receive code updates from a C2 server, Sality's spreading mechanism is a file infector: it propagated by attaching itself to executables on disk.\" The counterattack leverages an approach called peer list manipulation, which was also used in the 2014 GameOver Zeus and 2017 Kelihos botnet disruptions. It leverages the fact that Sality bots blindly trusted the P2P network without verifying who was added to it. As long as a machine was publicly reachable and responded correctly to the P2P handshake, it was accepted as a legitimate peer. This factor, coupled with the lack of authentication, cryptographic identity, or allowlist, meant that \"anyone\" could join the network as a full participant with no way to distinguish it from a genuinely infected host. The peer list manipulation technique, as the name implies, involves tampering with the peer list, a data structure containing a finite set of known super peers, which are publicly reachable infected machines that serve as the basis of the P2P network. The botnet checks whether its stored peers are still online every 40 minutes. Peers that respond to the check accumulate reputation, while those that fail lose reputation and are eventually purged. This maintenance cycle is abused to remove legitimate peers from the network via protocol-level manipulation during peer verification and insert purpose-built sinkhole entries into the emptied peer list. \"The disruption targets super peers first, as they form the network's communication backbone,\" CrowdStrike said. \"Once isolated, both URL packs and file packs stop propagating. The majority of infections sit behind firewalls or network address translation (NAT) and cannot be directly contacted.\" For these machines, a more passive approach is adopted. When they contact the sinkhole nodes during their normal maintenance cycles, their peer lists are purged, leaving them permanently isolated. The coordinated operation, besides sinkholing the P2P network, also takes down the URLs that have been found to host Sality payloads. In doing so, it prevents the malware from downloading these files and retrieving additional payloads. The list of URLs is below - theunforgiven.p8[.]hu\u002Fimg\u002Ftop.gif painelwebradiodigital.awardspace[.]info\u002Fv3\u002Freadme.pdf sgwebdesigner.free[.]fr\u002Fleft.gif www.yonelco[.]com\u002Ficon.png pozdravizbeograda[.]com\u002Freadme.pdf highclass.atspace[.]com\u002Fstyles.gif situluimihai.3x[.]ro\u002Ftop.png gatheredovertime[.]com\u002Fnb4 imagebucket[.]biz\u002Fnv4 All Sality-infected machines are now configured to beacon to CrowdStrike-operated sinkholes. Organizations are recommended to review network logs and endpoint telemetry for UDP traffic to the \"lighthouse\" IP address \"188.166.101[.]148.\" Any match indicates a Sality infection that requires remediation. \"This operation demonstrates that P2P architecture, long considered a shield against disruption, is not invincible,\" CrowdStrike said. \"With sufficient technical investment, precise understanding of protocol behavior, and coordination with law enforcement and industry partners, even the most resilient criminal infrastructure can be dismantled.\" \"While the disruption prevents new payloads from reaching infected machines, existing malware already installed on those systems remains active and should be removed.\" The dismantling is one of the key pillars under President Donald Trump's Cyber Strategy for America. Referred to as \"Shape Adversary Behavior,\" it aims to identify and disrupt malicious networks, scale national capabilities, and alter adversary calculus by degrading their tools and infrastructure. \"This unique collaboration among international law enforcement and private sector partners only enhances the FBI's cybersecurity capabilities and our efforts to neutralize the threat posed by the Sality botnet,\" said Patrick Grandy, the Assistant Director in Charge of the Federal Bureau of Investigation's (FBI) Los Angeles Field Office. \"The FBI will continue working with our partners to prevent further cyber-enabled attacks and theft from victims in the United St","https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fauthorities-turn-salitys-p2p-network.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEgDpXbKu79XC2ObZuqgBEMG9E1VR-SyLdDwhylzbIupomfXEbDe_gUT29NNntDVz9NtiGLhnHJdrq1GyC5RbPHozyzmCVov6JJIg2sCiCb5Jp8SHEInYNR5PRE06TrBh4Oqy8WT7GbTtGOZisMrKuCWaUWn5vaJkbHPmhTEb7O0voiiBDdYHcxc02YhLBb1\u002Fs1600\u002Fbotnet-malware.jpg","2026-09-02T06:56:30+00:00","2026-09-02T08:00:21.049843+00:00",8,[18,21,24,26,29,32],{"name":19,"type":20},"EggJagger","product",{"name":22,"type":23},"CrowdStrike","vendor",{"name":25,"type":23},"Shadowserver Foundation",{"name":27,"type":28},"P2P botnet","technology",{"name":30,"type":31},"Sality","threat_actor",{"name":33,"type":23},"Dragos","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":34,"icon":36,"name":37,"slug":38},null,"Malware","malware",[40,45,47,52],{"category":41},{"id":42,"icon":36,"name":43,"slug":44},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":46},{"id":34,"icon":36,"name":37,"slug":38},{"category":48},{"id":49,"icon":36,"name":50,"slug":51},"c5eccf7c-abbc-4bd3-bbed-e6da5cba8e73","Incident Response","incident-response",{"category":53},{"id":54,"icon":36,"name":55,"slug":56},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[58,62],{"type":59,"value":60,"context":61},"domain","forex2030.com","Targeted in a DDoS attack campaign attributed to Sality.",{"type":59,"value":63,"context":61},"kharkovforum.com"]