The record
Written from the 1 report below. Nothing here is unsourced.
- The U.S.
- Department of Justice announced a coordinated takedown of the long-running Sality peer-to-peer botnet, carried out on August 31, 2026 by authorities from the U.S., Bulgaria, Hungary, and Romania along with CrowdStrike and the Shadowserver Foundation.
- Sality is a Windows malware active since 2003 that infects executable files, spreads additional malicious software, and has delivered payloads including EggJagger, a clipboard tool used to steal at least $150,000 in cryptocurrency.
- The malware uses a peer-to-peer network instead of central command-and-control servers, making it resistant to conventional shutdown tactics and distributing payloads to more than 15,000 infected machines worldwide.
- The takedown used a peer list manipulation technique to insert sinkhole entries into the botnet's own network, isolating infected machines from the threat actor's control and blocking new payload downloads.
- The operation matters because it cut off a self-propagating botnet that had survived more than two decades and was believed to be operated from Russia's Republic of Bashkortostan.
What to watch next
- Whether the threat actor can rebuild or migrate to a new P2P network to restore control of infected machines
- Further details on the seized Sality-linked domains in the U.S. and Europe
- Whether additional variants or the reported version 3 and version 4 networks show signs of remaining activity
Who said what3
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Bill Essayli
First Assistant United States Attorney
2 quotes · 1 outlet
“Cybercriminals, botnets, and malware are a clear and present danger to our nation's security and economy”
In the article
…partners CrowdStrike and the Shadowserver Foundation. To that end, a peer-to-peer sinkhole operation was carried out to eliminate the threat. In tandem, Sality-linked domains have been seized in the U.S. and Europe. " Cybercriminals, botnets, and malware are a clear and present danger to our nation's security and economy ," said First Assistant United States Attorney Bill Essayli. "This successful effort to take down the Sality botnet shows that by working together, the public and private sectors can be a powerful force for good."…
“This successful effort to take down the Sality botnet shows that by working together, the public and private sectors can be a powerful force for good.”
In the article
…domains have been seized in the U.S. and Europe. "Cybercriminals, botnets, and malware are a clear and present danger to our nation's security and economy," said First Assistant United States Attorney Bill Essayli. " This successful effort to take down the Sality botnet shows that by working together, the public and private sectors can be a powerful force for good. " Sality has been documented in the wild since 2003, featuring capabilities to infect and modify Windows executable files, and spread additional malicious software designed for credential theft, spam distribution, proxy…
Patrick Grandy
1 quote · 1 outlet
“This unique collaboration among international law enforcement and private sector partners only enhances the FBI's cybersecurity capabilities and our efforts to neutralize the threat posed by the Sality botnet”
In the article
…for America. Referred to as "Shape Adversary Behavior," it aims to identify and disrupt malicious networks, scale national capabilities, and alter adversary calculus by degrading their tools and infrastructure. " This unique collaboration among international law enforcement and private sector partners only enhances the FBI's cybersecurity capabilities and our efforts to neutralize the threat posed by the Sality botnet ," said Patrick Grandy, the Assistant Director in Charge of the Federal Bureau of Investigation's (FBI) Los Angeles Field Office. "The FBI will continue working with our partners to prevent further cyber-enabled attacks…
Coverage1
All filed from India
Named United States · Bulgaria · Hungary · Romania · Russia · Ukraine · EggJagger · Sality · Bill Essayli · CrowdStrike · Department of Justice · Donald Trump · Dragos · Federal Bureau of Investigation · Patrick Grandy · Shadowserver Foundation
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
