Sality P2P Botnet Disrupted by Law Enforcement and CrowdStrike via Peer-List Sinkholing
Sality P2P Botnet Disrupted by Law Enforcement and (TL-2026-2284) is a high-severity malware campaign, first published 2026-09-01. It is linked to a Russia-nexus actor with medium confidence, affects Microsoft Windows (systems executing infected .exe/.scr files), maps to 16 MITRE ATT&CK techniques (T1005, T1014, T1027), and is covered by 9 detection rules and 11 indicators of compromise.
Key facts for TL-2026-2284
- Threat ID
- TL-2026-2284
- Severity
- HIGH
- Status
- MONITORING
- Category
- MALWARE
- First published
- 2026-09-01
- Last reviewed
- 2026-09-01
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target regions
- india, vietnam, morocco, united states of america, bulgaria, hungary, romania
- Detection rules
- 9
- Indicators of compromise
- 11
Malware and tooling in Sality P2P Botnet Disrupted by Law Enforcement and
Malware and tooling: EggJagger, Sality, Sality P2P peer-exchange overlay, Shadowserver sinkhole infrastructure
US and European law enforcement, working with CrowdStrike's Counter Adversary Operations team and the Shadowserver Foundation, dismantled Sality — a polymorphic file-infecting P2P botnet active since 2003 with over 15,000 infected machines worldwide — by poisoning bot peer lists with sinkhole entries and seizing associated domains. Sality's primary payload for roughly the past eight years, the clipboard-hijacking cryptocurrency stealer EggJagger, is estimated by CrowdStrike to have stolen at least $150,000.
How Sality P2P Botnet Disrupted by Law Enforcement and works
Sality is a polymorphic, entry-point-obscuring (EPO) file-infecting virus first identified in 2003 that targets Windows .exe and .scr files. Infection inserts polymorphic viral code into the final section of a host file, replaces the original entry point with a decryption stub, and launches a loader thread that pulls in the Sality payload — a design intended to defeat static antivirus signatures. Propagation is both local (recursive infection of drive C:, network-share infection via enumeration — MITRE ATT&CK Taint Shared Content) and removable-media based (USB drive infection paired with autorun.inf files for automatic execution on mount).
What makes Sality unusually durable is its command-and-control layer: rather than relying on centralized servers, infected hosts form a fully decentralized peer-to-peer overlay of up to roughly 1,000 preconfigured peers, exchanging encrypted UDP messages that carry lists of URLs for follow-on payloads. Because there is no single C2 server to seize, Sality has survived over two decades of attempted disruption. Since 2010, variants have added rootkit capability — device drivers with randomized filenames, process termination of security software via NtTerminateProcess, and IP filtering that blocks access to antivirus-vendor websites — and later versions are digitally signed to make hostile takeover of the peer network more difficult. The botnet's monetization stack layered credential theft (cached passwords, keystrokes), Outlook address-book harvesting, spam relay, HTTP proxy abuse, distributed password-cracking/computing tasks, and DDoS capability; for roughly the last eight years its dominant payload has been EggJagger, a clipboard-hijacking cryptocurrency stealer that silently swaps Bitcoin and Ethereum wallet addresses copied to the Windows clipboard for attacker-controlled addresses, which CrowdStrike estimates has netted at least $150,000.
The US Department of Justice, FBI, and the Department of Defense Office of Inspector General's Defense Criminal Investigative Service (DCIS), together with law enforcement in Bulgaria, Hungary, and Romania, coordinated a takedown built around Sality's core dependency: its peer list. CrowdStrike's Counter Adversary Operations team — which researcher Tillmann Werner called 'the most complex botnet takeover we have ever done' — seeded the P2P network with bogus peer-list entries that caused bots to remove legitimate super-peers and adopt sinkhole entries instead, isolating infected machines from the botnet's operators on a roughly 40-minute peer-verification cycle. CrowdStrike began the live technical takedown on August 31, 2026, in front of an audience at its Fal.Con 2026 'Day Zero' Threat Summit in Las Vegas; the DOJ and FBI publicly announced the operation on September 1, 2026, alongside the seizure of Sality-linked domains in the US and, by European partners, in Bulgaria, Hungary, and Romania. The Shadowserver Foundation coordinated with ISPs and CSIRTs on victim identification, notification, and remediation. DOJ officials confirmed the operation was 'based out of Russia' without further attribution detail; the Russian Embassy did not respond to comment requests.
No CVE or software vulnerability is involved — Sality spreads via file infection and removable/shared media rather than exploitation, so remediation is disinfection/reimaging plus peer-list and persistence cleanup rather than patching.
MITRE ATT&CK techniques used in TL-2026-2284
Collection
Defense Evasion
T1014 Rootkit; T1027 Obfuscated Files or Information; T1620 Reflective Code Loading
Credential Access
T1056.001 Input Capture: Keylogging; T1555 Credentials from Password Stores
Command and Control
T1071 Application Layer Protocol; T1090.002 Proxy: External Proxy; T1573.001 Encrypted Channel: Symmetric Cryptography
Lateral Movement
Initial Access
T1091 Replication Through Removable Media
Impact
Persistence
T1547.001 Registry Run Keys / Startup Folder
defense-impairment
T1553.002 Subvert Trust Controls: Code Signing; T1685 Disable or Modify Tools; T1688 Safe Mode Boot
Affected products and versions in Sality P2P Botnet Disrupted by Law Enforcement and
- Microsoft — Windows (systems executing infected .exe/.scr files)
Vulnerable versions: Any Windows version capable of executing infected .exe/.scr binaries or mounting infected removable/network media
Remediation for Sality P2P Botnet Disrupted by Law Enforcement and
Patches
- No CVE or vendor patch applies — Sality propagates through file infection and removable/shared media, not a software vulnerability; remediation is disinfection and reimaging of infected hosts
Immediate actions
- Identify and isolate hosts showing Sality/EggJagger indicators: disabled or non-functional antivirus, unexpected outbound UDP peer-exchange traffic, unauthorized Run-key entries, or missing Safe Mode registry keys
- Block outbound P2P peer-exchange UDP traffic and any residual Sality C2/proxy traffic at the network perimeter
- Restore Safe Mode boot registry entries and remove unauthorized HKCU/HKLM ...\Run persistence entries
- Rotate credentials and revoke sessions for any accounts whose passwords or keystrokes could have been captured on infected hosts
- Audit cryptocurrency transactions initiated from infected endpoints for clipboard-swapped wallet addresses
Workarounds
- Disable AutoRun/AutoPlay for removable media across the environment
- Restrict write access to network shares to limit propagation via infected shared files
- Monitor for clipboard-hijacking behavior (rapid, automated clipboard content changes matching cryptocurrency address patterns)
Longer-term hardening
- Deploy EDR with behavioral detection for rootkit driver loading, AV/security-process termination, and clipboard-monitoring API usage (SetClipboardViewer/AddClipboardFormatListener)
- Enforce application allow-listing and code-signing verification so Sality's own signed-but-illegitimate binaries and rogue Run-key/driver persistence are flagged
- Restrict and monitor write access to network shares and removable media to prevent Taint Shared Content / autorun reinfection
- Subscribe to Shadowserver victim-notification feeds to catch residual Sality infections identified via the disrupted sinkhole telemetry
Timeline of Sality P2P Botnet Disrupted by Law Enforcement and
- Sality first identified as a polymorphic, entry-point-obscuring Windows file-infector; its fully decentralized P2P architecture makes it resistant to centralized takedown from the outset.
- Sality variants add rootkit functionality — randomized device drivers, security-process termination, and IP filtering of antivirus-vendor sites.
- EggJagger, a clipboard-hijacking cryptocurrency stealer, becomes Sality's primary monetization payload, eventually netting an estimated $150,000+ in stolen Bitcoin and Ethereum.
- CrowdStrike seeds the Sality P2P network with poisoned peer-list entries, replacing legitimate super-peers with sinkholes and isolating infected hosts on a roughly 40-minute peer-verification cycle.
- CrowdStrike's Counter Adversary Operations team begins live dismantling of the Sality botnet before an audience at the Fal.Con 2026 'Day Zero' Threat Summit in Las Vegas.
- DOJ and FBI publicly announce the disruption; First Assistant U.S. Attorney Bill Essayli and FBI Assistant Director Patrick Grandy issue statements on the multinational operation.
- US DOJ, FBI, and DCIS seize Sality-linked domains domestically; law enforcement in Bulgaria, Hungary, and Romania seize additional Sality-linked domains hosted in Europe.
- The Register publishes detailed coverage of the takedown, peer-list poisoning technique, and EggJagger's cryptocurrency-theft impact.
Sources cited for Sality P2P Botnet Disrupted by Law Enforcement and
- Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes
- Russian Botnet Disrupted in International Cyber Operation (USAO-SDCA)
- Russian malicious software operation dismantled, feds in LA say
- Russian cybercrime operation being dismantled after two decades, US officials and CrowdStrike say
- Russian cybercrime operation being dismantled after two decades, US officials and CrowdStrike say
- CrowdStrike's Fal.Con 2026 Takes Over Mandalay Bay and Launches the Day Zero Threat Summit
- Sality Malware: Analysis, Detection, Removal
- Sality (Wikipedia)
More in malware
- Multi-Stage Cobalt Strike Loader Deploys Stageless Beacon via Anti-Sandbox .NET Chain
- Access-Code-Gated Phishing Chain Delivers Vidar Infostealer via DocuSign Impersonation
- ScarfaceStealer: Electron-Delivered Infostealer with Sandbox-Scoring Evasion and Smart-Contract C2
- Gigabud Android Banking Trojan Clones Banking Apps via Hidden Work Profile (Vwork/GoldFactory)
- LegionLoader Malware Distributed via Fake Cloudflare CAPTCHA Using the ClickFix Technique
Detection coverage for TL-2026-2284
As of 2026-09-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2284 across Splunk SPL, Microsoft KQL and Sigma, covering 11 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.