International Operation Disrupts Sality P2P Botnet, but Infected Devices Remain a Risk

The U.S. and European partners took action against the Sality P2P botnet. Sinkholing is intended to block delivery of new malicious payloads, but it does not remove existing infections.

The disruption of the Sality botnet resulted from a coordinated operation by the United States, Bulgaria, Hungary, and Romania carried out on August 31, 2026. The U.S. Department of Justice (DOJ) announced the action on September 1. The goal was to limit the operation of the long-active Sality malware and its decentralized P2P network, through which infected devices could obtain additional malicious components.

According to the DOJ, CrowdStrike and the nonprofit Shadowserver Foundation also participated in the operation. U.S. authorities seized domains associated with Sality in the United States, while partner authorities took action against additional related domains hosted in Europe.

Disrupting the Sality Botnet Through Its P2P Network

Sality is not an ordinary botnet dependent on a single central command server. It is a polymorphic file infector—that is, malware that infects executable files—which the DOJ says has been active since 2003. Its peer-to-peer architecture means compromised devices can exchange information directly with one another. This design complicates traditional interventions focused only on shutting down central infrastructure.

CrowdStrike said the operation used sinkholing and manipulation of P2P peer lists. Infected machines are therefore supposed to connect to infrastructure used in the operation instead of nodes controlled by the botnet operators. The purpose of this approach is to isolate devices from the network’s original control.

According to CrowdStrike, bots isolated this way should not receive new URL packs or file packs. These are instructions or files that may be used to deliver new malicious payloads. The operation therefore disrupts the ability to distribute additional malware through the existing P2P channel.

Sinkholing Does Not Mean the Computers Have Been Cleaned

A key limitation of the operation is that it does not remove Sality from systems that have already been compromised. CrowdStrike explicitly warned that malware already present on devices may remain active and requires separate remediation. Administrators therefore should not view sinkholing as a substitute for detecting, isolating, and cleaning the affected host.

Security teams should review their own telemetry for indicators of compromise published by CrowdStrike and address identified infections directly on the affected systems. Interrupting the communication channel alone may limit the receipt of new payloads, but it does not automatically remove existing malicious files.

CrowdStrike says there are more than 15,000 infected machines worldwide. However, this figure has not been publicly confirmed by government authorities or an independent third party. Likewise, the claim that the operator has completely and permanently lost control of all affected devices has not been independently measured.

What Comes Next

It has not been confirmed that the Sality operator was arrested. It also has not been publicly confirmed whether the actor will attempt to rebuild the infrastructure, prepare a new malware variant, or move victims to another control mechanism.

Shadowserver Foundation, internet service providers, and national CSIRT teams may provide further information if they publish the scope of identified victims or the results of notifications. Any court documents, lists of seized domains, or information about suspects from the DOJ and European partner authorities will also be important.

Sources

  • U.S. Department of Justice – Confirms the international operation, the seizure of domains in the United States, action against domains in Europe, and the participation of government and private-sector partners.
  • CrowdStrike – Describes the technical process of P2P sinkholing, manipulation of peer lists, blocking the distribution of new payloads, and the warning that existing malware remains on hosts.
  • SecurityWeek – Independently summarizes the announced operation and its technical mechanism.

Verified and updated: 09/02/2026 11:24

Sharing