Sality P2P Botnet Disrupted by Law Enforcement and CrowdStrike via Peer-List Sinkholing — Threadlinqs Intelligence
As of 2026-09-02, Sality P2P Botnet Disrupted by Law Enforcement and CrowdStrike via Peer-List Sinkholing is a high-severity malware threat attributed to a Russia-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 11 indicators of compromise.
Threat ID: TL-2026-2284 · Severity: HIGH · Status: MONITORING · Category: MALWARE
Attribution: Russia · FINANCIAL
US and European law enforcement, working with CrowdStrike's Counter Adversary Operations team and the Shadowserver Foundation, dismantled Sality — a polymorphic file-infecting P2P botnet active since
Sality is a polymorphic, entry-point-obscuring (EPO) file-infecting virus first identified in 2003 that targets Windows .exe and .scr files. Infection inserts polymorphic viral code into the final section of a host file, replaces the original entry point with a decryption stub, and launches a loader thread that pulls in the Sality payload — a design intended to defeat static antivirus signatures. Propagation is both local (recursive infection of drive C:, network-share infection via enumeration — MITRE ATT&CK Taint Shared Content) and removable-media based (USB drive infection paired with autorun.inf files for automatic execution on mount).
What makes Sality unusually durable is its command-and-control layer: rather than relying on centralized servers, infected hosts form a fully decentralized peer-to-peer overlay of up to roughly 1,000 preconfigured peers, exchanging encrypted UDP messages that carry lists of URLs for follow-on payloads. Because there is no single C2 server to seize, Sality has survived over two decades of attempted disruption. Since 2010, variants have added rootkit capability — device drivers with randomized filenames, process termination of security software via NtTerminateProcess, and IP filtering that blocks access to antivirus-vendor websites — and later versions are digitally signed to make hostile takeover of the peer network more difficult. The botnet's monetization stack layered credential theft (cached passwords, keystrokes), Outlook address-book harvesting, spam relay, HTTP proxy abuse, distributed password-cracking/computing tasks, and DDoS capability; for roughly the last eight years its dominant payload has been EggJagger, a clipboard-hijacking cryptocurrency stealer that silently swaps Bitcoin and Ethereum wallet addresses copied to the Windows clipboard for attacker-controlled addresses, which CrowdStrike estimates has netted at least $150,000.
The US Department of Justice, FBI, and the Department of Defense Office of Inspector General's Defense Criminal Investigative Service (DCIS), together with law enforcement in Bulgaria, Hungary, and Romania, coordinated a takedown built around Sality's core dependency: its peer list. CrowdStrike's Counter Adversary Operations team — which researcher Tillmann Werner called 'the most complex botnet takeover we have ever done' — seeded the P2P network with bogus peer-list entries that caused bots to remove legitimate super-peers and adopt sinkhole entries instead, isolating infected machines from the botnet's operators on a roughly 40-minute peer-verification cycle. CrowdStrike began the live technical takedown on August 31, 2026, in front of an audience at its Fal.Con 2026 'Day Zero' Threat Summit in Las Vegas; the DOJ and FBI publicly announced the operation on September 1, 2026, alongside the seizure of Sality-linked domains in the US and, by European partners, in Bulgaria, Hungary, and Romania. The Shadowserver Foundation coordinated with ISPs and CSIRTs on victim identification, notification, and remediation. DOJ officials confirmed the operation was 'based out of Russia' without further attribution detail; the Russian Embassy did not respond to comment requests.
No CVE or software vulnerability is involved — Sality spreads via file infection and removable/shared media rather than exploitation, so remediation is disinfection/reimaging plus peer-list and persistence cleanup rather than patching.
Target regions: india, vietnam, morocco, united states of america, bulgaria, hungary, romania
Timeline
- Sality first identified as a polymorphic, entry-point-obscuring Windows file-infector; its fully decentralized P2P architecture makes it resistant to centralized takedown from the outset.
- Sality variants add rootkit functionality — randomized device drivers, security-process termination, and IP filtering of antivirus-vendor sites.
- EggJagger, a clipboard-hijacking cryptocurrency stealer, becomes Sality's primary monetization payload, eventually netting an estimated $150,000+ in stolen Bitcoin and Ethereum.
- CrowdStrike's Counter Adversary Operations team begins live dismantling of the Sality botnet before an audience at the Fal.Con 2026 'Day Zero' Threat Summit in Las Vegas.
- CrowdStrike seeds the Sality P2P network with poisoned peer-list entries, replacing legitimate super-peers with sinkholes and isolating infected hosts on a roughly 40-minute peer-verification cycle.
- US DOJ, FBI, and DCIS seize Sality-linked domains domestically; law enforcement in Bulgaria, Hungary, and Romania seize additional Sality-linked domains hosted in Europe.
- DOJ and FBI publicly announce the disruption; First Assistant U.S. Attorney Bill Essayli and FBI Assistant Director Patrick Grandy issue statements on the multinational operation.
- The Register publishes detailed coverage of the takedown, peer-list poisoning technique, and EggJagger's cryptocurrency-theft impact.
Detections & IOCs
As of 2026-09-03, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 11 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1091, T1080, T1547.001, T1027, T1014, T1685, T1688, T1553.002, T1620, T1555