Security7 distinct publishers3 min readPublished
The August 31 operation cut the operator off from over 15,000 bots without cleaning a single disk. The Sality hosts on your network will stop calling home and keep infecting every executable they can write to.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Sality accepted anyone. A bot added any machine that was publicly reachable and answered the P2P handshake correctly, without authenticating itself, presenting any cryptographic identity, or being checked against an allowlist [10]. That is what the operation used: reachable nodes get accepted as peers, then a poisoned peer list propagates until the operator's real super peers are gone from every bot's address book [8]. The same peer list manipulation worked against GameOver Zeus in 2014 and Kelihos in 2017 [9].
The operator cannot answer this in software. Sality has no code update channel; it spreads as a file infector that attaches itself to executables on disk, which is why CrowdStrike says the protocol cannot be patched [11]. Pushing an authenticated version 5 to hosts already running the incompatible version 3 and version 4 protocols that were live at the time of the disruption is not possible [7]. CrowdStrike says the botnet is no longer under the operator's control [21].
The yield explains two decades of neglect. At least $150,000 taken through clipboard substitution [12], spread across the eight years EggJagger has been the primary payload [13], works out to roughly $18,750 a year [15]; divided across more than 15,000 infected machines [4] it is about $10 per victim host [14]. At that rate, funding a takedown never made business sense for any single victim.
The worm survives the sinkhole. Sality spread through infected network shares, USB devices, file sharing, compromised websites and email attachments, regenerating infections with no active effort from the operator [16]. That mechanism is untouched. A host infected next month will still write itself into every executable it can reach; it just will not receive EggJagger. For defenders the usual signal inverts: after August 31 the network chatter stops while the disk problem stays, so any infection inventory built from C2 callbacks will undercount. Dragos documented in July 2022 that Sality had reached industrial engineers and operators and pulled PLCs into the botnet [17], so OT asset owners do not get to file this as a desktop cleanup.
What is public is the seizure of Sality-linked domains in the U.S. and Europe [2] and the sinkhole itself, run with Europol and Eurojust support [3]. Attribution to a group tracked as SALTY SPIDER, likely operating out of the Republic of Bashkortostan in Russia, is CrowdStrike's assessment and is single-sourced here [18]. The reason the identification matters is history: CrowdStrike ties the same operator to DDoS campaigns against forex2030[.]com in April 2016, kharkovforum[.]com a day after Russia's full-scale invasion of Ukraine in February 2022, and AvanChange in September 2023 [19]. A clipper botnet that gets repointed at a Ukrainian forum inside 24 hours has a second use.
Joint disruptions have been common this year, and this one joins the list: the takedown of SocksEscort and the Aisuru, KimWolf, JackSkid and Mossad C2 infrastructure in March, and Dutch authorities taking a 17-million-device botnet offline in May [23].
Ranked by verification strength, evidence, and original report placement.
The U.S. Department of Justice announced the takedown of the Sality P2P botnet; the operation was undertaken on August 31, 2026 by authorities from the U.S., Bulgaria, Hungary and Romania in collaboration with CrowdStrike and the Shadowserver Foundation, including a peer-to-peer sinkhole operation and seizure of Sality-linked domains in the U.S. and Europe.
The DOJ, FBI and DCIS seized Sality-linked domains in the United States, while law enforcement partners in Bulgaria, Hungary and Romania seized additional Sality-linked domains hosted in Europe.
The disruption was carried out with the DOJ, FBI, DCIS and the Shadowserver Foundation, with support from Europol, Eurojust and law enforcement agencies in Bulgaria, Hungary and Romania.
Sality has been documented in the wild since 2003 and infects and modifies Windows executable files, spreading additional malware for credential theft, spam distribution, proxy services, network exploitation and DDoS.
Two independent Sality P2P networks, known as version 3 and version 4, remained active until the disruption; CrowdStrike says they shared the same codebase and operator but used incompatible protocol versions and different cryptographic keys.
The botnet was disrupted by sinkholing Sality's list of known super peers, which form its communication backbone, to block file packs (direct payload transfers) and URL packs (payload download instructions) from propagating and to purge infected machines' peer lists.
Follow any of these and your For You feed starts watching them — no settings page required.
product
CrowdStrike talked a 23-year-old botnet into disconnecting itself1 distinct publisher
security
FBI names Nanjing contractor behind 300-victim Check Point Quantum Gateway campaign1 distinct publisher
invest
Washington licenses private hacking, and hands the contractor the liability1 distinct publisher
security
DoJ rewrites its QTFY seizure release to move seven agencies from victims to targets1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
bleepingcomputer.com
1 article · September 2, 2026
crowdstrike.com
1 article
cyberscoop.com
1 article · September 2, 2026
helpnetsecurity.com
1 article · September 2, 2026
securityweek.com
1 article · September 2, 2026
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Six retellings, one telemetry source
Two institutional accounts underpin everything here: a Justice Department announcement and CrowdStrike's technical writeup. The protocol mechanics, the 15,000 machines, the $150,000, the eight-year EggJagger window and the Bashkortostan assessment all originate with the vendor that ran the operation, and five outlets repeat them without independent verification. Recorded Future News is the exception that raises the floor, adding Reuters interviews with CrowdStrike's Tillmann Werner and Shadowserver's David Watson. The one figure nobody else can match, CyberScoop's 11 million devices, is also the one nobody sourced.
Fully executed, barely remediated
The action itself is done and verifiable in effect: sinkholes are live, the domains that hosted Sality's malware files are seized on both continents, and CrowdStrike says every surviving bot now beacons to its infrastructure. What has not happened is cleanup. Shadowserver is still trying to work out through ISPs and national response teams who owns those 15,000-plus machines, and notification is where this reporting stops. No disk was touched, so the file infector keeps writing itself into executables on every host that was infected on August 30.
'Irrecoverable' outruns the receipts
The operational claim is modest and well supported; the language wrapped around it is not. CyberScoop calls the malware-spreading operation irrecoverable and prints CrowdStrike's 'we will find you' peroration, yet Recorded Future News establishes that nobody was arrested, the operator is unnamed, and no one can say whether the botnet gets rebuilt. Add an unsourced 11-million-device count and a $150,000 haul, roughly the annual salary of one person, presented as the prize, and the rhetoric sits a step ahead of what was actually demonstrated: a hard, elegant piece of protocol work that stranded 15,000 still-infected computers.
The only technical witness is also the vendor
CrowdStrike ran the operation, wrote the account everyone quotes, and closes its post with a pledge to take the fight to adversaries; its blog is a sales document as much as a research one, and CyberScoop reprints the sharpest lines from it. On the government side, Bill Essayli's public-private 'force for good' quote appears in three outlets verbatim, and Recorded Future News records officials tying the takedown to the first pillar of the administration's cyber strategy. The publishers have their own pull too: BleepingComputer's page ends in a promotion for a vendor threat report. None of this makes the technical work wrong; it does mean nobody in this story is disinterested.
Solid on what happened, thin on what changed
Confidence is high for the operation and its mechanics: the date, partners, seizures and peer-list method are consistent across independent outlets and a government announcement, and the technique has documented precedent in the GameOver Zeus and Kelihos disruptions. It drops on scale and aftermath, where the counts conflict between CyberScoop and everyone else, the theft estimate is an explicit floor with unmeasured side revenue, and remediation of 15,000 infected hosts is a notification effort still under way.
thehackernews.com
1 article · September 1, 2026
therecord.media
1 article · September 2, 2026