www.infosecurity-magazine.com 9/3/2026, 8:58:19 AM · external

International Operation Disrupts Sality P2P Botnet

International Operation Disrupts Sality P2P Botnet

A recent international law enforcement operation, led by the US, has significantly disrupted the Sality P2P botnet, which has been active for over 20 years. The operation, conducted on August 31, involved collaboration between authorities from Bulgaria, Hungary, Romania, and the US, supported by Europol and private partners such as CrowdStrike and the Shadowserver Foundation.

The operation utilized a method known as 'sinkholing' to redirect communications from infected devices, effectively countering the decentralized nature of P2P botnets. By manipulating the botnet's peer verification process, the operation was able to purge legitimate peers and insert sinkhole entries, aiding in infection tracking and victim notification. Sality has historically compromised over one million machines, facilitating various cybercriminal activities, including credential theft and DDoS attacks.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline