On August 31, 2026, U.S. and European authorities, CrowdStrike and the Shadowserver Foundation disrupted the Sality botnet by seizing operator linked domains and sinkholing its peer to peer network.
Published byEdited with GPT-5.6 TerraImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: What was the coordinated September 2026 operation by CrowdStrike, the FBI, the U.S. Justice Department, European law enforcement, and other. Article summary: On August 31, 2026, a multinational public-private operation disrupted—not necessarily permanently eradicated—the Sality peer-to-peer botnet. It combined U.S. legal seizures, cooperation by Bulgaria, Hungary, and Romania. Topic tags: general, government, general web, user generated, news. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermark
Sality was disrupted in a coordinated international operation on August 31, 2026. The effort paired court-backed domain seizures with a technical peer-to-peer (P2P) sinkhole operation that redirected infected computers away from infrastructure controlled by the botnet’s operator. It involved the U.S. Justice Department, FBI and Defense Criminal Investigative Service; authorities in Bulgaria, Hungary and Romania; CrowdStrike; and the Shadowserver Foundation. 1
6
7
U.S. authorities seized Sality-linked domains used to control compromised devices and distribute malicious payloads. Authorities in Bulgaria, Hungary and Romania took action against additional infrastructure in their jurisdictions. 1
6
But domain seizures alone were not enough. Sality was designed as a P2P botnet: infected machines could exchange information about other infected machines, rather than relying entirely on a small, fixed set of command-and-control servers. That decentralization helped the network remain operational even when individual servers or domains disappeared. 6
7
CrowdStrike’s Counter Adversary Operations team therefore conducted a P2P sinkhole operation alongside law enforcement and industry partners. The goal was to isolate the infected devices and render the operator’s command channel inert. 1
7
CrowdStrike reverse-engineered the botnet’s P2P communications and targeted the peer-list mechanism—the information compromised devices used to find one another. Researchers identified weaknesses in how that information was accepted and propagated, then seeded the network with false peer information. 6
13
In practical terms, the operation caused infected systems to connect toward controlled sinkhole infrastructure instead of the operator’s network. That blocked the operator from using the active network to issue new download instructions or deliver additional payloads. 6
7
This was unusually complex because investigators were not simply removing a central server. They had to counter a distributed system in which infected machines could independently share network information. The operation needed legal action against domains and a synchronized technical intervention that could overtake the botnet’s own discovery process. 1
6
7
Sality had operated for more than two decades and was used to deliver malicious payloads to infected machines. Reporting and official accounts describe its use in spam activity, distributed-denial-of-service attacks, credential theft and cryptocurrency theft. 6
One reported payload, EggJagger, monitored a victim’s clipboard for cryptocurrency wallet addresses and replaced them with an attacker-controlled address, potentially redirecting intended Bitcoin or Ethereum transfers. CrowdStrike estimated that EggJagger alone had stolen at least $150,000 in cryptocurrency. 6
The Shadowserver Foundation was a private-sector partner in the multinational disruption, working alongside CrowdStrike and law-enforcement agencies. The Justice Department identified both organizations as collaborators in the coordinated effort to disrupt Sality and take down its infrastructure. 1
That partnership mattered because botnet disruptions are not purely technical or legal exercises. Domain seizures require legal authority and international coordination; sinkholing requires specialized technical analysis and operational execution. Combining both reduced the operator’s ability to reach the compromised network. 1
7
A disrupted botnet is not the same as every infected device being cleaned. CrowdStrike said Sality had enabled the distribution of malicious payloads to more than 33,000 infected machines worldwide. 7
For defenders, an infected endpoint can still represent a potential foothold: it may contain malware, have been exposed to credential theft, or require investigation for follow-on activity. The sinkhole cuts off the active command path described by the operation, but organizations still need to identify and remediate affected systems.
The longer-term outcome is also uncertain. Sality’s operator has not been publicly identified, and the available reporting supports describing the action as a disruption rather than proof that the threat can never return. The operator could attempt to regain access, alter the malware, or establish replacement infrastructure. 1
7
Sality’s takedown shows why P2P botnets can be durable—and why dismantling them demands more than taking down a few servers. Its decentralized design helped it persist for years, but the same peer-discovery machinery gave investigators a route to isolate the network when reverse engineering, sinkholing and international legal action were coordinated effectively. 1
6
7
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
On August 31, 2026, U.S. and European authorities, CrowdStrike and the Shadowserver Foundation disrupted the Sality botnet by seizing operator linked domains and sinkholing its peer to peer network.
On August 31, 2026, U.S. and European authorities, CrowdStrike and the Shadowserver Foundation disrupted the Sality botnet by seizing operator linked domains and sinkholing its peer to peer network. Sality survived conventional takedowns because compromised computers shared peer information rather than depending solely on a few central servers.
Organizations with infected systems still need remediation: a sinkholed machine may be isolated from the operator, but the malware and any prior exposure remain a security concern.