U.S., Bulgarian, Hungarian, and Romanian authorities, supported by CrowdStrike and the Shadowserver Foundation, disrupted the long-running Sality peer-to-peer botnet by seizing payload-hosting domains, dismantling control infrastructure, and sinkholing its super-peer network. The operation exploited Sality's unauthenticated peer-list protocol to redirect infected hosts away from operator-controlled infrastructure, cutting off delivery of new malware payloads and removing the botnet from the operators' control.
Active since at least 2003, Sality infected more than 15,000 devices and spread by infecting Windows executables. CrowdStrike attributes the operation to SALTY SPIDER, a criminal group likely based in Russia's Republic of Bashkortostan; its infrastructure supported credential theft, spam, proxying, network exploitation, DDoS activity, and EggJagger cryptocurrency clipboard hijacking. Organizations should investigate UDP communications with 188.166.101[.]148, an indicator of Sality infection, because sinkholing prevents new payload delivery but does not remove malware from already compromised systems.

Pull IOCs and campaign context straight into your stack.
8 events from the most recent confirmed update back to the earliest known activity.
The U.S. Department of Justice announced the coordinated Sality disruption. CrowdStrike assessed that the operation removed the botnet from operator control, although sinkholing does not remove malware already installed on infected systems.
Authorities in the United States, Bulgaria, Hungary, and Romania, supported by CrowdStrike and the Shadowserver Foundation, conducted a coordinated disruption of Sality. The operation seized Sality-linked domains and used peer-list manipulation and sinkholes to isolate infected hosts, remove super peers, and block payload transfers and download instructions.
Sality targeted AvanChange in a distributed denial-of-service attack.
Dragos reported that a Sality campaign targeted industrial engineers and operators in an effort to take control of programmable logic controllers and enlist them in the botnet.
Sality targeted the Ukrainian Forum website kharkovforum[.]com in a DDoS attack, one day after Russia's full-scale invasion of Ukraine.
Sality targeted the Arabic Financial Forum website forex2030[.]com in a distributed denial-of-service attack.
Sality was observed in the wild and active by 2003, infecting and modifying Windows executable files and using multiple propagation methods.
CrowdStrike attributed Sality to the SALTY SPIDER group, which it assesses operates from Russia's Republic of Bashkortostan. It said Sality had primarily delivered the EggJagger cryptocurrency clipper for the prior eight years and that operators stole at least $150,000 in cryptocurrency.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
20 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourceinfosec.pub
Open sourcecysecurity.news
Open sourcexakep.ru
Open sourcecyberveille.ch
Open sourcejustice.gov
Open sourcecrowdstrike.com
Open sourceeuropol.europa.eu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.