As part of a concerted law enforcement effort, the U.S. Department of Justice (DoJ) stated on Tuesday that the long-running peer-to-peer (P2P) botnet known as Sality had been taken down.
Authorities from the United States, Bulgaria, Hungary, and Romania launched the initiative on August 31, 2026, working with private industry partners CrowdStrike and the Shadowserver Foundation. In order to remove the danger, a peer-to-peer sinkhole operation was conducted. Concurrently, Sality-related domains have been taken over in Europe and the United States.
First Assistant US Attorney Bill Essayli stated that malware, botnets, and cybercriminals pose a serious threat to the security and economics of our country. This successful attempt to dismantle the Sality botnet demonstrates how the public and private sectors can be a potent force for good when they collaborate.
Since 2003, Sality has been known to infect and alter Windows executable files as well as disseminate other malicious software intended for network exploitation, credential theft, spam distribution, proxy services, and distributed denial-of-service (DDoS) assaults.
Under the names Salty Spider, Kukacka, Sality, KuKu, SalLoad, Kookoo, and SaliCode, the threat actor responsible for the virus is being monitored by the larger cybersecurity community. It is thought that the gang is based in Russia’s Republic of Bashkortosta read more about Authorities Turn Sality’s P2P Network Against Itself Cutting Off New Malware Payloads
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
