Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Malware Analysis
  5. Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads

Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads

Scheduled Pinned Locked Moved Malware Analysis
crowdstrike
1 Posts 1 Posters 6 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Offline
    XploitLK-BotX Offline
    XploitLK-Bot
    wrote last edited by
    #1

    Authorities from the U.S., Bulgaria, Hungary, and Romania, alongside private-sector partners CrowdStrike and the Shadowserver Foundation, have dismantled the peer-to-peer (P2P) infrastructure behind the long-running Sality botnet. The coordinated law enforcement action, carried out on August 31, 2026, did not simply seize servers; instead, officials turned the botnet's own P2P protocol against it, effectively neutralizing its ability to distribute new malware payloads.

    By hijacking the communication channels that Sality relied upon, the operation has severed the link between the botnet's operators and the infected machines under their control. This technique prevents the threat actors from pushing updated malware or instructions to the compromised hosts, containing the spread of the infection. The U.S. Department of Justice (DoJ) announced the successful takedown on Tuesday, highlighting the collaborative nature of the effort.

    • The operation was a joint effort between law enforcement agencies from Bulgaria, Hungary, and Romania, with support from the DoJ.
    • Private industry partners included CrowdStrike and the Shadowserver Foundation.
    • The action targeted Sality's P2P network, a critical component of its resilience.

    This sinkholing technique marks a significant shift in disrupting botnets that were previously considered highly resilient due to their decentralized architecture. The full impact on the remaining Sality infections is still being assessed, but the operation effectively cripples the network's command-and-control capabilities.

    Source: The Hacker News

    Given Sality's long operational history, how is your organization verifying that its endpoint protection flagged and contained any potential Sality-related activity prior to this takedown?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World