logo

International Operation Disrupts Sality P2P Botnet

ID: 6522f1df-0cb7-53bc-b448-031de34de626

STIX ID: report--6522f1df-0cb7-53bc-b448-031de34de626

Feed Name: Infosecurity Magazine (News)

Threat Score
78/100

Date Published: 2026-09-03

Date Updated: 2026-09-11

...
...

A US-led international law-enforcement operation, supported by Europol and private partners CrowdStrike and Shadowserver, disrupted the Sality P2P botnet that has operated for over 20 years and at its peak infected hundreds of thousands to millions of machines. The disruption relied on sinkholing via protocol-level manipulation of peer verification—removing legitimate peers from bots' lists and inserting sinkhole entries—to track and notify victims and aid remediation across multiple jurisdictions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.