CrowdStrike, international law enforcement agencies, and industry partners disrupted the long-running Sality peer-to-peer botnet by manipulating its peer-discovery mechanism. The operation reportedly removed legitimate super peers from bot peer lists and inserted sinkholes, severing the operator’s ability to distribute URL packs and file packs to compromised systems while allowing defenders to track infections. Partners also took down URLs hosting Sality payloads.
The disruption prevents affected Sality v3 and v4 bots from receiving new tasking, but it does not remove the malware or payloads previously delivered to infected endpoints. CrowdStrike published sinkhole IP addresses, URL indicators, and YARA rules to help organizations identify active infections and should be used alongside endpoint remediation to eradicate existing malware.

Pull IOCs and campaign context straight into your stack.
7 events from the most recent confirmed update back to the earliest known activity.
The Sality operator's never-spent cryptocurrency portfolio peaked at approximately ₽147 million, according to CrowdStrike's assessment.
A Sality DDoS payload targeted AvanChange, a Russian cryptocurrency exchange platform. The payload was compiled seconds before upload to distribution infrastructure, suggesting a possible impulsive personal grievance.
Sality distributed a DDoS payload against kharkovforum.com, a Ukrainian forum discussing Russia's military offensive against Kharkiv. CrowdStrike assessed the activity as likely patriotically motivated and apparently intended to suppress discussion of Russia's invasion of Ukraine.
A Sality DDoS payload targeted forex2030.com, an Arabic-language site covering natural-resource trading companies, and rendered the site unresponsive.
CrowdStrike identified 188.166.101.148 as a sinkhole lighthouse IP, with UDP traffic to it indicating a Sality infection requiring remediation. It also released URL-pack indicators and YARA rules CrowdStrike_Salityv3_01 and CrowdStrike_Salityv4_01 for detecting active infections.
The U.S. Justice Department, FBI, and Defense Criminal Investigative Service seized Sality-linked domains, while authorities in Bulgaria, Hungary, and Romania acted against additional domains hosted in Europe. The Shadowserver Foundation began supporting ISPs and CSIRTs with identifying infections, victim notification, and remediation.
CrowdStrike, international law enforcement, and industry partners disrupted the long-running Sality botnet by manipulating peer lists, removing legitimate super peers, and inserting sinkholes. The operation reportedly severed the operator's ability to communicate with infected hosts and coordinated takedowns of payload-hosting URLs.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 13 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.