The U.S. Department of Justice (DoJ) has announced the disruption of Sality, a long running peer to peer (P2P) botnet that has been active for more than two decades. The coordinated operation was conducted on August 31, 2026, by authorities from the United States, Bulgaria, Hungary, and Romania, with support from private sector cybersecurity organizations including CrowdStrike and the Shadowserver Foundation. The operation used a P2P sinkhole technique to take control of the botnet communication network and prevent infected systems from receiving new malware payloads. Authorities also seized Sality linked domains in the U.S. and Europe as part of the wider effort to reduce the threat posed by the malware infrastructure.
Sality has been active since 2003 and has remained a significant malware threat due to its ability to infect and modify Windows executable files while spreading additional malicious software. Over the years, the malware has been used to distribute different types of harmful payloads associated with credential theft, spam campaigns, proxy services, network exploitation, and distributed denial of service (DDoS) attacks. The threat actor connected to Sality is tracked by the cybersecurity community under several names, including Salty Spider, Kukacka, Sality, KuKu, SalLoad, Kookoo, and SaliCode. The group is believed to operate from the Republic of Bashkortostan in Russia. Unlike traditional malware that relies on centralized command and control (C2) servers, Sality developed P2P communication capabilities, allowing it to continue operations even when individual infrastructure components were disrupted. One of the primary payloads associated with Sality is EggJagger, a clipper tool that monitors clipboard activity for cryptocurrency wallet addresses and replaces legitimate wallet information with addresses controlled by the operators. Researchers estimate that this method resulted in at least $150,000 in cryptocurrency theft. Although financial activity has been a major focus of Sality operations, the botnet has also been used in several DDoS campaigns targeting different online platforms. These included an Arabic Financial Forum in April 2016, a Ukrainian Forum in February 2022, shortly after Russia launched its full scale invasion of Ukraine, and AvanChange in September 2023. Sality has spread through multiple methods, including infected network shares, USB devices, file sharing platforms, compromised websites, email attachments, and P2P networks, creating a self propagating infection system that could continue expanding without continuous involvement from operators.
According to CrowdStrike, Sality operators were able to distribute malicious payloads to more than 15,000 infected machines worldwide. Two separate P2P networks, known as version 3 and version 4, remained active before the disruption. Although both networks shared the same codebase and were operated by the same threat actor, they used different protocol versions and cryptographic keys. The disruption operation focused on exploiting weaknesses in Sality communication methods by turning the botnet own P2P structure against itself. Authorities and cybersecurity partners used peer list manipulation to isolate infected machines from operator controlled peers and prevent payload downloads. The technique takes advantage of the fact that Sality systems trusted network participants without verifying identity through authentication, cryptographic validation, or allowlists. The peer list manipulation process targeted super peers, which act as the communication foundation of the P2P network. Sality regularly checks whether stored peers remain active, rewarding responsive systems while removing those that fail verification. Researchers used this maintenance process to remove legitimate peers and insert sinkhole entries into the network. Once super peers were isolated, the distribution of URL packs and file packs stopped. Machines operating behind firewalls or network address translation (NAT) were handled through a passive approach, where their peer lists were cleared when they connected with sinkhole systems during routine maintenance.
The operation also removed URLs that were identified as hosting Sality related payloads, preventing infected systems from downloading additional files. CrowdStrike stated that all Sality infected machines are now configured to communicate with cybersecurity operated sinkholes. Organizations have been advised to review network logs and endpoint telemetry for UDP traffic linked to the lighthouse IP address 188.166.101[.]148, as any communication may indicate a Sality infection requiring remediation. Researchers noted that while the disruption prevents new payload delivery, existing malware already installed on affected systems remains active and must be removed. CrowdStrike said the operation demonstrates that P2P based malware infrastructure can be disrupted through technical analysis, coordinated action, and cooperation between public and private sector organizations. The FBI also highlighted the importance of international collaboration in reducing cyber risks and preventing further attacks linked to malware networks. The joint operation forms part of broader efforts to identify and disrupt malicious infrastructure by reducing the capabilities available to cybercriminal networks.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.