Sality's P2P Network Turned Against Itself, Cutting Off New Malware Payloads
On August 31, 2026, U.S., Bulgarian, Hungarian, and Romanian authorities, collaborating with CrowdStrike and Shadowserver Foundation, successfully disrupted the Sality botnet through a peer-to-peer sinkhole operation. Active since 2003, Sality infects Windows executables and spreads malware for credential theft, spam distribution, and DDoS attacks. The botnet delivered EggJagger clipper malware, stealing at least $150,000 through cryptocurrency wallet substitution. The takedown exploited Sality's P2P architecture weakness by manipulating peer lists, isolating over 15,000 infected machines from threat actor control. This peer list manipulation technique prevented payload distribution by inserting sinkhole entries and removing legitimate peers. Associated domains were seized across U.S. and Europe. While the disruption stops new payloads, existing infections remain active requiring remediation. The operation demonstrates that resilient P2P criminal infrastructure can be dismantled through coordinated law enf...
Indicators of Compromise
- domain: www.yonelco.com
- domain: pozdravizbeograda.com
- url: http://theunforgiven.p8.hu/img/top.gif
- url: http://www.yonelco.com/icon.png
- url: http://pozdravizbeograda.com/readme.pdf
- url: http://gatheredovertime.com/nb4
- url: http://imagebucket.biz/nv4
- domain: forex2030.com
Sality's P2P Network Turned Against Itself, Cutting Off New Malware Payloads
Description
On August 31, 2026, U.S., Bulgarian, Hungarian, and Romanian authorities, collaborating with CrowdStrike and Shadowserver Foundation, successfully disrupted the Sality botnet through a peer-to-peer sinkhole operation. Active since 2003, Sality infects Windows executables and spreads malware for credential theft, spam distribution, and DDoS attacks. The botnet delivered EggJagger clipper malware, stealing at least $150,000 through cryptocurrency wallet substitution. The takedown exploited Sality's P2P architecture weakness by manipulating peer lists, isolating over 15,000 infected machines from threat actor control. This peer list manipulation technique prevented payload distribution by inserting sinkhole entries and removing legitimate peers. Associated domains were seized across U.S. and Europe. While the disruption stops new payloads, existing infections remain active requiring remediation. The operation demonstrates that resilient P2P criminal infrastructure can be dismantled through coordinated law enf...
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://thehackernews.com/2026/09/authorities-turn-salitys-p2p-network.html"]
- Adversary
- null
- Pulse Id
- 6a97f2b0566cf1ccb1ec8fb4
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainwww.yonelco.com | — | |
domainpozdravizbeograda.com | — | |
domainforex2030.com | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://theunforgiven.p8.hu/img/top.gif | — | |
urlhttp://www.yonelco.com/icon.png | — | |
urlhttp://pozdravizbeograda.com/readme.pdf | — | |
urlhttp://gatheredovertime.com/nb4 | — | |
urlhttp://imagebucket.biz/nv4 | — |
Threat ID: 6a980a7aacd9273b492f5491
Added to database: 09/02/2026, 11:37:30 UTC
Last updated: 09/02/2026, 11:37:30 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.