The Shadowserver Foundation: 23-Year-Old Sality P2P Botnet Disrupted

The Shadowserver Foundation: 23-Year-Old Sality P2P Botnet Disrupted

Sality P2P Botnet Disrupted After 23 Years in Global Law Enforcement Operation

After more than two decades of operation, the Sality peer-to-peer (P2P) botnet one of the longest-running malware networks has been dismantled in a coordinated international takedown. First detected in 2003, Sality evolved into a versatile cybercriminal tool, distributing information stealers, DDoS payloads, proxy services, and cryptocurrency-stealing malware.

In its later years, Sality primarily deployed EggJagger, a clipjacking tool that hijacked cryptocurrency transactions, siphoning at least $150,000 in Bitcoin and Ethereum. Its resilience stemmed from a decentralized architecture, spreading via infected executables on disks and removable media while avoiding reliance on a central command-and-control (C&C) server.

However, Sality’s trust-based P2P protocol which lacked authentication became its downfall. Bots periodically verified "super peers" (infected machines forming the network’s backbone), purging inactive ones. CrowdStrike exploited this mechanism by manipulating peer lists, isolating infected devices, and injecting sinkholes to sever communication with the botnet’s operators.

The operation, led by law enforcement in the U.S., Bulgaria, Hungary, and Romania, also involved takedowns of Sality payload-hosting URLs, preventing reinfection. CrowdStrike confirmed that all compromised machines now beacon to its sinkholes, cutting off the botnet’s control. Meanwhile, The Shadowserver Foundation is collaborating with ISPs and CSIRTs to identify and remediate infected systems.

The disruption marks the end of one of cybercrime’s most enduring threats, though its legacy underscores the challenges of combating decentralized malware networks.

Source: https://www.securityweek.com/23-year-old-sality-p2p-botnet-disrupted/

The Shadowserver Foundation TPRM report: https://www.rankiteo.com/company/the-shadowserver-foundation

"id": "the1788345212",
"linkid": "the-shadowserver-foundation",
"type": "Cyber Attack",
"date": "9/2026",
"severity": "25",
"impact": "1",
"explanation": "Attack without any consequences"
{'affected_entities': [{'location': 'Global',
                        'name': 'Global infected machines',
                        'type': 'End-user devices'},
                       {'location': 'Global',
                        'name': 'Cryptocurrency users',
                        'type': 'Individuals/Organizations'}],
 'attack_vector': ['Infected executables on disks', 'Removable media'],
 'data_breach': {'data_exfiltration': True,
                 'sensitivity_of_data': 'High (financial)',
                 'type_of_data_compromised': 'Cryptocurrency transaction data'},
 'date_detected': '2003',
 'description': 'After more than two decades of operation, the Sality '
                'peer-to-peer (P2P) botnet, one of the longest-running malware '
                'networks, has been dismantled in a coordinated international '
                'takedown. First detected in 2003, Sality evolved into a '
                'versatile cybercriminal tool, distributing information '
                'stealers, DDoS payloads, proxy services, and '
                'cryptocurrency-stealing malware. In its later years, Sality '
                'primarily deployed EggJagger, a clipjacking tool that '
                'hijacked cryptocurrency transactions, siphoning at least '
                '$150,000 in Bitcoin and Ethereum. Its resilience stemmed from '
                'a decentralized architecture, spreading via infected '
                'executables on disks and removable media while avoiding '
                'reliance on a central command-and-control (C&C) server. The '
                'disruption marks the end of one of cybercrime’s most enduring '
                'threats, though its legacy underscores the challenges of '
                'combating decentralized malware networks.',
 'impact': {'data_compromised': 'Cryptocurrency transaction data',
            'financial_loss': '$150,000 (cryptocurrency stolen)',
            'operational_impact': 'Disruption of botnet operations',
            'payment_information_risk': 'Cryptocurrency transaction hijacking',
            'systems_affected': 'Infected machines globally'},
 'investigation_status': 'Disrupted',
 'lessons_learned': 'The challenges of combating decentralized malware '
                    'networks and the importance of exploiting vulnerabilities '
                    'in trust-based protocols for disruption.',
 'motivation': ['Financial gain', 'Data theft', 'Cryptocurrency theft'],
 'post_incident_analysis': {'corrective_actions': ['Sinkholing botnet '
                                                   'communication',
                                                   'Takedown of '
                                                   'payload-hosting URLs',
                                                   'Collaboration with '
                                                   'ISPs/CSIRTs for '
                                                   'remediation'],
                            'root_causes': 'Decentralized P2P architecture, '
                                           'lack of authentication in '
                                           'trust-based protocol, infected '
                                           'executables and removable media'},
 'references': [{'source': 'Cybersecurity news outlets'}],
 'response': {'containment_measures': ['Manipulating peer lists to isolate '
                                       'infected devices',
                                       'Injecting sinkholes to sever '
                                       'communication'],
              'law_enforcement_notified': True,
              'remediation_measures': ['Takedowns of Sality payload-hosting '
                                       'URLs',
                                       'Collaboration with ISPs and CSIRTs to '
                                       'remediate infected systems'],
              'third_party_assistance': 'CrowdStrike, The Shadowserver '
                                        'Foundation'},
 'threat_actor': 'Sality botnet operators',
 'title': 'Sality P2P Botnet Disrupted After 23 Years in Global Law '
          'Enforcement Operation',
 'type': 'Botnet Disruption',
 'vulnerability_exploited': 'Trust-based P2P protocol without authentication'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.