At a Glance
| Malware family | Sality peer-to-peer (P2P) botnet; EggJagger clipper payload |
| Threat actor | Single operator (unnamed); attribution not publicly confirmed |
| Victims | Over 15,000 infected machines; 11M+ IPs linked historically |
| Delivery vector | File-infecting virus spreading via executables, USB, shares |
| Key capabilities | Payload distribution, credential theft, spam, DDoS, crypto clipping |
| Source | Europol press release; CrowdStrike Counter Adversary Operations |
TL;DR
On 31 August 2026, law enforcement and industry partners disrupted the Sality botnet. The operation used a peer-to-peer sinkhole to isolate infected machines. As a result, the operator lost control of a network that ran for more than 20 years.
A Two-Decade Criminal Network
The Sality botnet first appeared in 2003 as a file-infecting virus. Over time, its operator turned it into a resilient P2P malware platform. According to Europol, the coordinated action was led by US authorities and targeted “a botnet believed to have been operating for more than two decades.”
At its peak, the botnet gave its operator access to up to one million machines. To date, more than 11 million unique IP addresses have been linked to the infrastructure. Bulgaria, Hungary, Romania, and the United States joined the takedown, with Europol, CrowdStrike, and the Shadowserver Foundation.
Delivery and Infection Chain
Sality spread by attaching itself to Windows executables. Infected files then travelled across network shares, USB drives, and file-sharing networks. Each bot maintained a list of “super peers,” publicly reachable machines that formed the network backbone. Every 40 minutes, a bot checked whether those peers were still online.
Command-and-Control and Payloads
Unlike central-server botnets, Sality bots communicated directly with one another. Europol notes this “decentralised structure makes them particularly resilient and difficult to dismantle.” For eight years, its main payload was EggJagger, a clipboard clipper. It swapped copied cryptocurrency wallet addresses for attacker-controlled ones. CrowdStrike estimates the operator stole at least $150,000 this way.
How the Sality Botnet Was Sinkholed
Investigators turned the P2P design against itself. They poisoned peer lists with sinkhole entries and purged legitimate peers. This “isolated compromised devices from the botnet and rendered the operator’s command channel inoperable.” Meanwhile, the DOJ, FBI, and DCIS seized Sality-linked domains, and European partners seized more.
Defense and Detection Guidance
The Shadowserver Foundation is now notifying affected owners through ISPs and national CSIRTs. Administrators should watch for classic file-infector signs, such as unexpected changes to executables and outbound P2P traffic. Keeping systems patched and restricting USB autorun both reduce exposure. Victim remediation of the Sality botnet remains ongoing.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!