"Cybercriminals, botnets, and malware are a clear and present danger to our nation's security and economy," said First Assistant United States Attorney Bill Essayli.
How authorities turned Sality's P2P network against itself
On August 31, 2026, law enforcement and private partners executed a peer-to-peer (P2P) sinkhole operation that deliberately manipulated Sality's own network protocols to isolate infected hosts from the threat actor. The technique — known as peer list manipulation — exploited core design choices in Sality's P2P stack: bots blindly accepted any publicly reachable peer that responded correctly to the P2P handshake, and the protocol lacked authentication, cryptographic identity, or an allowlist.
Sality maintains a finite peer list of publicly reachable "super peers" that form the network backbone. The botnet's maintenance cycle checks stored peers every 40 minutes; peers that respond gain reputation while those that fail are purged. Investigators abused that cycle to remove legitimate super peers and insert purpose-built sinkhole entries. Once super peers were isolated, "both URL packs and file packs stop propagating," CrowdStrike said, and machines behind firewalls or NAT that cannot be directly contacted were rendered inert when they contacted the sinkhole nodes during their normal maintenance cycles.
Sality's capabilities, payloads, and notable campaigns
Sality has been observed in the wild since 2003. It is a file infector that attaches itself to Windows executable files and can spread via infected network shares, USB devices, file sharing, compromised websites, email attachments, and P2P networks. Because it modifies executables on disk, CrowdStrike noted, "Sality's P2P protocol cannot be patched." Unlike conventional malware that can receive code updates from a C2 server, Sality's spreading mechanism is baked into infected files.
One primary payload distributed via Sality is EggJagger, a clipper or clipjacking tool that monitors clipboard contents for cryptocurrency wallet addresses and substitutes actor-controlled addresses to redirect transactions. The source estimates threat actors have stolen at least $150,000 using that method.
Although largely financially motivated, Sality has also been repurposed for DDoS campaigns. CrowdStrike documented three notable attacks:
- Arabic Financial Forum ("forex2030[.]com") in April 2016
- Ukrainian Forum ("kharkovforum[.]com") in February 2022, a day after Russia's full-scale invasion of Ukraine
- AvanChange in September 2023
In July 2022, Dragos disclosed a campaign that targeted industrial engineers and operators to seize control of Programmable Logic Controllers (PLCs) and co-opt those devices into the Sality botnet.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleInternational partners, domain seizures, and operational details
The takedown was announced by the U.S. Department of Justice and executed in coordination with authorities from the United States, Bulgaria, Hungary, and Romania, alongside private industry partners CrowdStrike and the Shadowserver Foundation. In addition to sinkholing the P2P network, Sality-linked domains were seized in the U.S. and Europe and a set of known payload-hosting URLs were taken down to prevent further downloads.
The operation named specific URLs that had hosted Sality payloads, including:
- theunforgiven.p8[.]hu/img/top.gif
- painelwebradiodigital.awardspace[.]info/v3/readme.pdf
- sgwebdesigner.free[.]fr/left.gif
- www.yonelco[.]com/icon.png
- pozdravizbeograda[.]com/readme.pdf
- highclass.atspace[.]com/styles.gif
- situluimihai.3x[.]ro/top.png
- gatheredovertime[.]com/nb4
- imagebucket[.]biz/nv4
All Sality-infected machines are now configured to beacon to CrowdStrike-operated sinkholes. Organizations were specifically advised to review network logs and endpoint telemetry for UDP traffic to the "lighthouse" IP address "188.166.101[.]148"; any match indicates a Sality infection requiring remediation.
Patrick Grandy, the Assistant Director in Charge of the Federal Bureau of Investigation's Los Angeles Field Office, said: "This unique collaboration among international law enforcement and private sector partners only enhances the FBI's cybersecurity capabilities and our efforts to neutralize the threat posed by the Sality botnet." The FBI added it will continue working with partners "to prevent further cyber-enabled attacks and theft from victims in the United States."
What this means for technologists and security teams, the FBI and policymakers, and affected organizations
Technologists and security teams: Confirm whether endpoints or network sensors show UDP traffic to "188.166.101[.]148" and remediate any machines that beacon there. Remember that the disruption prevents new payloads from reaching infected machines but does not remove malware already installed; CrowdStrike warned that existing malware remains active and should be removed.
The FBI and policymakers: The operation was identified as a practical implementation of the "Shape Adversary Behavior" pillar in President Donald Trump's Cyber Strategy for America, which aims to identify and disrupt malicious networks, scale national capabilities, and degrade adversary tools and infrastructure. The takedown provides a model for coordinated international action against resilient P2P criminal infrastructure.
Affected organizations and end users: If EggJagger or other payloads were present, financial theft via clipboard substitution has already occurred—estimated at a minimum of $150,000—and infected hosts may have been used in past DDoS campaigns. Review endpoint telemetry and remove compromised binaries; take special care in environments with OT equipment after Dragos' July 2022 findings that PLCs were targeted.
Authority over the botnet's communication backbone has been disrupted, but the malware binaries still exist on disks. The immediate gain is clear: new payload distribution is blocked and the P2P network is sinkholed. The lingering obligation is equally clear: defenders must find and clean the infections that remain active on hosts across the internet.




