Sality Botnet Disruption: How the P2P Sinkhole Cut Its Command Path
A multinational operation disrupted Sality's peer-to-peer command path across more than 15,000 infected hosts. This analysis explains the sinkhole technique and the remediation checks defenders still need to perform.

Incident Summary
A multinational operation disclosed on September 1, 2026 disrupted the Sality botnet, a peer-to-peer malware network that had operated for more than two decades. U.S. and European law-enforcement partners combined domain seizures with a protocol-level sinkhole operation.
CrowdStrike said the operator could distribute malicious payloads to more than 15,000 infected hosts worldwide. The operation altered peer relationships and redirected bots toward controlled sinkholes.
Disclosed Facts
The Justice Department said actions took place in the United States, Bulgaria, Hungary, and Romania. Shadowserver is supporting internet service providers and incident-response teams with victim identification, notification, and remediation.
Two separate networks, Sality v3 and v4, remained active before the disruption and used incompatible protocols and different cryptographic keys. URL packs pointed bots to additional payloads, while file packs delivered malicious content.

How the P2P Disruption Worked
Sality's infected systems exchanged peer lists and relied on highly connected super peers to circulate URL and file packs. The operation invalidated legitimate super-peer entries, inserted sinkhole entries, and removed payload-hosting URLs.
Systems behind firewalls or NAT were redirected when they contacted the sinkhole during ordinary maintenance cycles. That stopped the propagation path and severed the operator's command channel.
CrowdStrike published 188.166.101[.]148 as a lighthouse IP for identifying Sality infections. UDP traffic to that address should be preserved as a detection signal and tied back to the source host.
Response Checks
Because Sality infects executable files, response should extend beyond terminating one process. Teams should isolate the host, preserve evidence, scope shared paths and removable media, and decide whether trusted-image rebuilding is safer than file-by-file repair.
- Search network and endpoint telemetry for communications with 188.166.101[.]148.
- Isolate each source host and preserve volatile and file-change evidence.
- Scope executable files on shares and removable media.
- Decide between repair and trusted-image rebuild.
- Rotate potentially exposed credentials and verify that traffic does not recur.
Domain seizures and sinkholing weaken criminal control but do not repair infected files on victim systems. Containment, scope, eradication, credential rotation, and reconnection validation remain local responsibilities.

Impact
The operation is especially relevant to organizations that maintain older Windows estates, removable media workflows, shared executables, or long-lived endpoints. A sinkhole match should lead to host remediation rather than only a block-list entry.
Korean organizations with overseas offices, legacy business networks, or partners using older systems can apply the same network check and recovery sequence.
Official Sources
This article is based on the U.S. Department of Justice announcement and CrowdStrike's technical account. Reuters' publication timestamp placed the disclosure within this research window.
Sources reviewed
- Sality Malware Disrupted in International Cyber TakedownU.S. Department of Justice · Official source
- Peer Pressure: Inside the Sality Botnet Disruption OperationCrowdStrike · Official source
- Russian cybercrime operation being dismantled after two decades, US officials and CrowdStrike sayReuters
SECUFOCUS NOW reorganized and analyzed the material above. This article does not replace the original sources.



Comments
No comments yet.