CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5530

As cited

Copy frozen at (site build).

threat intel

Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads

The U.S. Department of Justice coordinated with authorities in Bulgaria, Hungary, and Romania, along with CrowdStrike and the Shadowserver Foundation, to take down the Sality peer-to-peer (P2P) botnet on August 31, 2026. The operation disrupted the long-running malware infrastructure by turning its own network against it to prevent distribution of new payloads.

Why it matters: Organizations running systems infected with Sality should verify remediation efforts, as the disrupted command and control infrastructure may affect bot functionality and detection patterns.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads

The U.S. Department of Justice coordinated with authorities in Bulgaria, Hungary, and Romania, along with CrowdStrike and the Shadowserver Foundation, to take down the Sality peer-to-peer (P2P) botnet on August 31, 2026. The operation disrupted the long-running malware infrastructure by turning its own network against it to prevent distribution of new payloads.

Why it matters: Organizations running systems infected with Sality should verify remediation efforts, as the disrupted command and control infrastructure may affect bot functionality and detection patterns.

VendorsCrowdStrike
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary