International law enforcement agencies, in collaboration with cybersecurity firm CrowdStrike and the Shadowserver Foundation, have successfully disrupted the Sality peer-to-peer botnet, which has been active for 23 years. The operation, which took place on Monday, September 1, 2026, involved a peer-to-peer sinkhole strategy designed to isolate infected machines and sever the botnet operator's control.
Sality, first identified in 2003, has been used to distribute various forms of malicious code to over 15,000 machines globally. Its capabilities have included credential theft, spam distribution, proxy services, network exploitation, and distributed denial-of-service (DDoS) attacks. For the past eight years, the botnet's primary payload has been EggJagger, a tool that monitors clipboards for cryptocurrency wallet addresses and replaces them with attacker-controlled addresses, redirecting funds during transactions.
CrowdStrike estimates that the Sality operator stole at least $150,000 in cryptocurrency through the use of EggJagger alone. The disruption aimed to break the botnet's functionality by preventing infected devices from receiving new payload download instructions or direct payload transfers.
The counterattack exploited a core mechanism of the Sality botnet: its peer list. Each Sality bot maintains a list of "super peers," which are publicly reachable infected machines forming the backbone of the P2P network. Bots check the status of their peers every 40 minutes, purging unresponsive ones. The disruption strategy involved systematically removing legitimate super peers from each bot's list and inserting purpose-built sinkhole entries. This process progressively isolated more infected machines and provided law enforcement and cyber operatives with visibility into the operation's progress, aiding in victim notification.
In addition to the sinkhole operation, the U.S. Justice Department, the FBI, and the Department of Defense Office of Inspector General’s Defense Criminal Investigative Service seized Sality-linked domains within the United States. Concurrently, law enforcement agencies in Bulgaria, Hungary, and Romania took action against additional Sality-linked domains hosted in Europe.
The Shadowserver Foundation is now working with internet service providers and Computer Security Incident Response Teams (CSIRTs) to identify infected machines and assist with victim notification and remediation efforts.






