Sality Botnet Takedown: How a 23-Year-Old P2P Network Was Turned Against Itself
By Sethu Satheesh · 11 Sept 2026 · 20 min read
Threat Actor: SALTY SPIDER (CrowdStrike designation; unattributed, no charges) · Target: Windows hosts worldwide (~33,000 at disruption); cryptocurrency users via clipboard hijacking; industrial engineering workstations
Source: www.justice.gov
Executive Summary
On Monday 31 August 2026, CrowdStrike's Counter Adversary Operations team, working with the US Department of Justice, the FBI, the Defense Criminal Investigative Service, the Shadowserver Foundation, Europol, Eurojust and police in Bulgaria, Hungary and Romania, executed a peer-to-peer sinkholing operation against Sality, a Windows file-infecting botnet first recorded in June 2003. In parallel, US authorities seized Sality-linked domains in the United States and the three European partners acted against payload-hosting domains in Europe. The operator has lost the ability to send new tasking to infected machines; the two surviving networks, protocol versions 3 and 4, now report to sinkholes operated by CrowdStrike.
Sality had no central command server to seize. Every infected machine kept a list of up to a thousand publicly reachable "super peers" and, every forty minutes, checked which of them were still answering. Peers that responded gained reputation; peers that did not lost it and were eventually purged. There was no authentication of any kind: any host that spoke the protocol correctly was accepted as a peer. The operation exploited that maintenance cycle to invalidate legitimate super-peer entries and replace them with purpose-built sinkholes, working from the reachable backbone inward. Machines behind NAT, which could not be contacted directly, isolated themselves the next time their own maintenance cycle brought them to a sinkhole.
Two features of this case are unusual. First, the protocol being attacked was not a secret. Symantec published a full analysis of it in July 2011, including the forty-minute cycle, the reputation counter and the purge thresholds, and concluded that the design was robust against a single rogue peer. Because Sality spreads by infecting executables on disk, its operator could never push a protocol update without competing with the existing strain for the same host files; the behaviour documented in 2011 was the behaviour attacked in 2026. Second, the public record on scale is inconsistent. CrowdStrike's own write-up said "over 15,000 infected machines" when published on 1 September and was changed to "over 33,000" between 3 and 4 September without an editor's note; Europol, describing the same operation, said the botnet had reached "up to one million infected machines" at its peak and that "more than 11 million unique IP addresses" had been linked to it over its lifetime. These figures measure different things over different periods, and this paper sets out which is which.
Nobody has been charged. CrowdStrike tracks the operator as SALTY SPIDER and assesses it is "likely operating out of the Republic of Bashkortostan in Russia"; the 2011 Symantec paper records that the malware's name derives from "Salavat City", a town in Bashkortostan, and that the author's early versions signed themselves "Sector". The DOJ release describes domain seizures but names no court, warrant or order, in contrast to the disclosed Rule 41 process in the 2017 Kelihos takedown and the civil injunction in the 2014 GameOver Zeus action. For the past eight years Sality's main payload was EggJagger, a clipboard hijacker that swapped cryptocurrency addresses at the moment of payment; CrowdStrike estimates at least ₽12.1 million (about US$150,000) was stolen that way, which is a small return for infrastructure that ran for twenty-three years.
Verification of Claims
-
Claim: The disruption was executed on 31 August 2026. → Verified → DOJ press release of 1 September 2026 ("On Monday"); CrowdStrike blog, 1 September 2026; Europol press release, 2 September 2026. All three give the same date.
-
Claim: Sality has been active since 2003. → Verified → Symantec, 2011: "The first public occurrence of Sality was recorded in June 2003." DOJ, 2026: "Since 2003, the Sality botnet has installed malicious software…"
-
Claim: The botnet had over 15,000 infected machines. → Partially verified — superseded by the source → CrowdStrike's post carried this figure at publication (Wayback Machine, 2 and 3 September snapshots). The same sentence read "over 33,000" from the 4 September snapshot onward. No correction notice was added. BleepingComputer, The Hacker News, Help Net Security and SecurityWeek all published the 15,000 figure and have not updated it.
-
Claim: At its peak the botnet gave the operator access to up to one million machines. → Partially verified → Europol, 2 September 2026, without a date or method. The likely basis is Symantec's July 2011 measurement that a rogue peer "communicates with more than a million unique IP addresses" a day on the V3 network, which Symantec itself qualified as "potentially a million peers". Unique IPs over-count machines on dynamic addressing and under-count them behind NAT.
-
Claim: More than 11 million unique IP addresses have been linked to the infrastructure. → Unverified → Europol states it; neither the observation period nor the method is given, and no partner has published corroborating telemetry. Shadowserver, the partner most likely to hold the data, has not published on it as of 11 September 2026.
-
Claim: The operator is based in Bashkortostan, Russia. → Partially verified — vendor assessment → CrowdStrike: "likely operating out of the Republic of Bashkortostan." The 2011 Symantec paper records that "Sality" derives from "Salavat City, a Russian town from which the author may originate"; Salavat is in Bashkortostan. Whether CrowdStrike holds evidence beyond that 2003-era string is not published. No law enforcement body has attributed the botnet to anyone.
-
Claim: EggJagger stole at least ₽12.1 million (~US$150,000). → Partially verified → CrowdStrike's estimate, described as covering the EggJagger payload only. The method (presumably tracing the substituted addresses on-chain) is not described. CrowdStrike separately states the unspent holdings peaked at about ₽147 million in January 2025.
-
Claim: The peer-list technique is the same class used against GameOver Zeus in 2014 and Kelihos in 2017. → Verified → CrowdStrike states this directly. The 2014 DOJ GameOver Zeus release and the 2017 DOJ Kelihos release both describe redirecting infected machines' peer-to-peer communications to substitute servers.
-
Claim: The protocol attacked in 2026 was publicly documented in 2011. → Verified → Symantec's whitepaper describes the forty-minute cycle ("The client then waits 40 minutes before the above steps are repeated"), the "goodcount" reputation value, the 1,000-entry peer-list limit and the purge threshold. CrowdStrike's 2026 description of the maintenance cycle matches it point for point.
-
Claim: A court order or warrant authorised the sinkhole. → Unverified → The DOJ release does not mention one. A search of CourtListener/RECAP for "Sality" in the Central District of California and nationally on 11 September 2026 returned no matching docket. This is what was looked for and not found, not a statement that no process exists; sealed applications are routine in botnet cases.
Timeline
| Date | Actor | Event | Source |
|---|---|---|---|
| June 2003 | Sality author | First public occurrence. Early versions prepend UPX-packed code to executables, keylog, and email stolen data via Russian SMTP servers. Strings reference "Salavat City", "Kuku" and the nickname "Sector". | Symantec 2011 |
| 2006 | Sality author | Version 3.09 becomes polymorphic, adds anti-security routines, and downloads payloads from hardcoded HTTP domains. | Symantec 2011 |
| Early 2008 | Sality author | Protocol V2 introduces peer-to-peer distribution of URL packs. | Symantec 2011 |
| 2009 | Sality author | Protocol V3, which becomes the largest network. | Symantec 2011 |
| Late 2010 | Sality author | Protocol V4: 2048-bit RSA key, signed executables, direct peer-to-peer EXE transfer over TCP. | Symantec 2011 |
| July 2011 | Symantec | Publishes "Sality: Story of a Peer-to-Peer Viral Network". V3 super peers steady at 8,000–10,000; over a million unique IPs contact a rogue peer daily. | Symantec 2011 |
| April 2016 | Sality operator | DDoS payload against forex2030[.]com, an Arabic-language financial forum. | CrowdStrike 2026 |
| 2017 | Europol | Begins supporting multi-jurisdiction work to identify and take down Sality infrastructure. | Europol 2026 |
| 25 February 2022 | Sality operator | DDoS payload against kharkovforum[.]com, one day after Russia's full-scale invasion of Ukraine. | CrowdStrike 2026 |
| 14 July 2022 | Dragos | Reports trojanised PLC "password recovery" tools that exploit CVE-2022-2003 in DirectLogic PLCs and drop Sality on engineering workstations. | Dragos 2022 |
| September 2023 | Sality operator | DDoS payload against AvanChange, a Russian cryptocurrency exchange; compiled seconds before upload. | CrowdStrike 2026 |
| January 2025 | Sality operator | EggJagger's unspent cryptocurrency holdings peak at about ₽147 million. | CrowdStrike 2026 |
| 18 August 2026 | CrowdStrike | Date on the YARA rules later published with the disruption write-up. | CrowdStrike 2026 |
| August 2026 | Partners | Weekly operational calls in the weeks before the action. | Europol 2026 |
| 31 August 2026 | CrowdStrike, DOJ, FBI, DCIS, BG/HU/RO police | Peer-to-peer sinkhole executed; US seizes Sality-linked domains; European partners act against payload-hosting domains. | DOJ, CrowdStrike, Europol |
| 1 September 2026 | DOJ; CrowdStrike | DOJ (C.D. Cal.) announces the operation. CrowdStrike publishes its write-up: "over 15,000 infected machines". | DOJ 2026; Wayback |
| 2 September 2026 | Europol | Europol release: "up to one million infected machines" at peak; "more than 11 million unique IP addresses". | Europol 2026 |
| 3–4 September 2026 | CrowdStrike | Blog figure changed from 15,000 to 33,000 with no correction note. | Wayback snapshots |
Operation Anatomy
What was attacked: the peer list
Sality has no command server. Each infected host holds a local list of up to 1,000 super peers, publicly reachable infected machines that form the backbone of the network. Symantec's 2011 analysis documents the maintenance loop that every bot runs:
- The client thread iterates over its peer list, sending a UDP query to each super peer. The port is derived from the computer name (
Port = C + f(ComputerName); one implementation used2199 + CompName[last] * CompName[first]). - Each peer's
goodcountis incremented if it answers according to the protocol and decremented if it does not. Goodcounts are local to each bot and are never exchanged. - Peers whose goodcount falls below a threshold (recent implementations: −30) are discarded, but only when the list still holds a minimum number of entries (recent implementations: 500).
- The client asks each responding peer for a new peer, and the server "replies with a peer randomly taken from its peerlist, and whose goodcount is strictly positive".
- The client then waits 40 minutes and repeats.
Command distribution rides on the same loop. A "URL pack" is a signed list of URLs pointing to payloads on compromised or operator-controlled web servers; bots exchange pack sequence numbers with their peers and fetch anything newer. V4 added signed "EXE packs" transferred peer-to-peer over TCP on the UDP port plus 19. Signatures are verified against an RSA public key hardcoded in every infected file, which is also why the two networks, V3 and V4, are cryptographically separate: a new key means a new network.
There is no authentication at the signalling layer. CrowdStrike, 2026: "Any machine that was publicly reachable and responded correctly to the P2P handshake was accepted as a legitimate peer. There was no authentication, no cryptographic identity, no allowlist."
Why it could never be fixed
Sality is a file infector. It persists by attaching itself to executables on disk and spreads through network shares, removable media and file sharing. That gave it two decades of regeneration without any campaign effort from the operator, and it also removed the operator's ability to change the protocol: a new variant would compete with the existing strain for the same host files and fragment the network rather than upgrade it. CrowdStrike: "The protocol behavior that bots exhibit today is the same it exhibited 20 years ago. Every weakness in that protocol is permanent."
The 2011 whitepaper is therefore not history; it is a description of the target as it existed on 31 August 2026. The kernel driver it describes, registered as service amsint32, used an IPFilter callback available only on Windows XP, 2000 and 2003 to drop packets to security-vendor websites. That mechanism has been inert on every supported Windows version for fifteen years, but the string IPFILTERDRIVER is still in the binary, and it is one of the two anchors in CrowdStrike's 2026 YARA rules.
Stage 1: super peers
Loading diagram...
The operation targeted the backbone first. CrowdStrike describes two moves inside the verification cycle: "protocol-level manipulation during peer verification allows legitimate super peer entries to be invalidated in each bot's peer list", and "purpose-built sinkholes are injected into the emptied peer lists". The specific manipulation is not published.
Symantec's 2011 analysis sets the constraints any such technique had to satisfy, and they are worth stating because the paper concluded the design was sound. Junk coordinates supplied through peer exchange can only overwrite entries whose goodcount is already negative. Only peers with strictly positive goodcount are propagated to others. The server thread never adjusts goodcounts; only the client thread does, and only in response to its own queries. Falliere's conclusion: "It seems that no single rogue peer could seriously destabilize the botnet."
The word doing the work there is single. The one path that moves a goodcount is the bot's own query, and a sinkhole that always answers correctly is the one kind of peer whose goodcount only ever rises. Sinkholes are therefore always positive, always propagated, and never purged, while genuine super peers are residential machines that go offline and lose reputation. ThreatPaper's reading, which CrowdStrike has neither confirmed nor described, is that the operation combined an active step against legitimate entries during verification with a passive ratchet in which the reputation system itself, run at scale by peers that never fail, converged every list on the sinkholes. The technique is described by CrowdStrike as the same class used against GameOver Zeus in 2014 and Kelihos in 2017, "adapted here for Sality's specific protocol behavior".
Stage 2: everything behind NAT
Most infections cannot be reached from the internet. For those, CrowdStrike states a "more passive approach": when the bot's own maintenance cycle brings it to a sinkhole, its peer list is purged, "leaving them permanently isolated". From the operator's side, "infected machines simply disappear."
Stage 3: payload URLs
In parallel, the domains hosting the current URL packs were taken down: the DOJ, FBI and DCIS seized US-hosted domains, and Bulgarian, Hungarian and Romanian police acted against domains hosted in Europe. This closes the window in which a bot still carrying an unexpired URL pack could fetch a payload before its peer list was poisoned. The last V3 pack (version 25202) pointed at seven files on free-hosting and compromised sites in Hungary, France, Romania, Serbia and elsewhere; the last V4 pack (version 31010) pointed at two.
What the sinkhole now sees
Every remaining infection beacons over UDP to a CrowdStrike-operated "lighthouse" address, 188.166.101[.]148, in a DigitalOcean range in the Netherlands. Shadowserver is using the resulting telemetry to notify ISPs and national CSIRTs. The malware on each host is not removed by any of this; the executables remain infected and EggJagger remains resident until the machine is remediated.
Threat Actor Profile
- Name / Alias: SALTY SPIDER (CrowdStrike). Also tracked as Kukacka, SalLoad, Kookoo, SaliCode; the 2003 strings "Kuku" and "Sector" (Symantec).
- Attribution confidence: Low. No law enforcement body has attributed the botnet to any person. CrowdStrike assesses the operator is "likely" in Bashkortostan; the only published basis is the "Salavat City" string recorded by Symantec in 2011. Nobody is charged.
- Motivation: Financial, with three documented exceptions where the botnet was turned to DDoS: an Arabic financial forum (2016), a Ukrainian forum discussing the invasion of Kharkiv (25 February 2022), and a Russian cryptocurrency exchange (2023). CrowdStrike reads the second as "patriotic" and the third as "an impulsive reaction to a personal grievance".
- Sophistication: High in 2003–2010, when the P2P design and the V4 hardening were built; effectively static since. Symantec found the client and server routines "well coded and immune to buffer or integer overflows".
- Scale of operation: CrowdStrike describes "a single criminal actor operating with minimal overhead to maintain an infrastructure that runs itself."
- MITRE ATT&CK techniques (verified on attack.mitre.org, 11 September 2026):
- T1091 Replication Through Removable Media
- T1080 Taint Shared Content
- T1027.002 Obfuscated Files or Information: Software Packing
- T1055 Process Injection
- T1014 Rootkit (kernel driver
amsint32) - T1685 Disable or Modify Tools (process killer; packet filter against security-vendor sites)
- T1095 Non-Application Layer Protocol (custom UDP signalling)
- T1105 Ingress Tool Transfer (URL packs, EXE packs)
- T1115 Clipboard Data and T1565.002 Transmitted Data Manipulation (EggJagger)
- T1090 Proxy; T1498 Network Denial of Service (historical payloads)
- T1056.001 Keylogging (2003-era payload)
Technical Indicators
# Source: CrowdStrike, 1 September 2026; Symantec, July 2011. Defanged.
sinkhole:
lighthouse_ip: 188.166.101[.]148 # UDP; any traffic = active Sality infection
note: CrowdStrike-operated; DigitalOcean NL range
last_url_packs:
v3_version_25202:
- hxxp://theunforgiven.p8[.]hu/img/top.gif
- hxxp://painelwebradiodigital.awardspace[.]info/v3/readme.pdf
- hxxp://sgwebdesigner.free[.]fr/left.gif
- hxxp://www.yonelco[.]com/icon.png
- hxxp://pozdravizbeograda[.]com/readme.pdf
- hxxp://highclass.atspace[.]com/styles.gif
- hxxp://situluimihai.3x[.]ro/top.png
v4_version_31010:
- hxxp://gatheredovertime[.]com/nb4
- hxxp://imagebucket[.]biz/nv4
host:
service_name: amsint32 # kernel driver service (Symantec 2011)
yara_anchor_string: IPFILTERDRIVER
yara_rules: CrowdStrike_Salityv3_01, CrowdStrike_Salityv4_01 (memory scan for hardcoded RSA keys; see source 2)
network_behaviour:
transport: UDP, port derived from computer name
peer_cycle: every 40 minutes
v4_exe_transfer: TCP on UDP port + 19Legal and Regulatory Response
United States. The operation was announced by the US Attorney's Office for the Central District of California on 1 September 2026, press release 26-149. The Justice Department, FBI Los Angeles Field Office and DCIS "seized Sality-linked domains in the United States". Assistant US Attorney Lauren Restrepo of the National Security Division led the US effort. The release frames the action under the "Shape Adversary Behavior" pillar of the administration's Cyber Strategy for America. It does not name a court, a warrant, an order, a defendant or a suspect. DCIS's participation, and its statement about "protecting the integrity of the Department of Defense Information Network", indicate Sality infections touching DoD networks; no detail is given.
Europe. Europol's European Cybercrime Centre and the Joint Cybercrime Action Taskforce coordinated Bulgaria's General Directorate Combating Organised Crime, Hungary's National Bureau of Investigation Cybercrime Department and Romania's Directorate for Combating Organised Crime, with Eurojust. CrowdStrike and Shadowserver participated under Europol's Cyber Intelligence Extension Programme. The action was carried out under the EMPACT policy cycle. Europol states its involvement dates to 2017.
Compared with precedent. The 2014 GameOver Zeus action was accompanied by a criminal complaint and civil injunction in the Western District of Pennsylvania and named Evgeniy Bogachev. The 2017 Kelihos action rested on a Rule 41 warrant from the District of Connecticut, disclosed at the time, authorising redirection of infected machines to a substitute server, and followed the arrest of Peter Levashov in Barcelona. The Sality release discloses neither charges nor process. A search of CourtListener/RECAP on 11 September 2026 found no docket mentioning Sality.
Victim notification. Shadowserver is providing sinkhole data to ISPs and national CSIRTs. No regulator has issued guidance specific to this operation.
Impact Assessment
- Operator control severed — Confirmed. CrowdStrike, DOJ and Europol all state the command channel is inoperable. Existing infections persist.
- Infected machines at disruption — Reported, contested. "Over 15,000" (CrowdStrike, 1–3 September; still in all press coverage); "over 33,000" (CrowdStrike, from 4 September). Whether the change reflects sinkhole telemetry accumulating after day one, or a correction, is not stated.
- Lifetime scale — Reported. "Up to one million" machines at peak and "more than 11 million unique IP addresses" (Europol). Symantec measured over a million unique IPs per day in July 2011; unique IPs are not machines.
- Cryptocurrency stolen — Estimated. At least ₽12.1 million (~US$150,000) via EggJagger over eight years (CrowdStrike). Other payload families are not included.
- Geographic distribution — Reported. CrowdStrike published a map without figures. In 2011 the top countries for V3 super peers were Romania, India and Brazil.
- DDoS victims — Confirmed by vendor telemetry. forex2030[.]com (2016), kharkovforum[.]com (2022), AvanChange (2023).
- Industrial systems — Reported. Dragos documented Sality delivered through trojanised PLC password tools in 2022, with moderate confidence that the intent was financial rather than disruptive.
- Operator identity — Unknown. No charges, no named suspect.
- Legal authority for the sinkhole — Unknown. Not disclosed.
Lessons and Defensive Recommendations
For SOC and IR teams
- Alert on any UDP traffic to 188.166.101[.]148. A match is a confirmed infection, not a false positive.
- Run CrowdStrike's two YARA rules against process memory across the estate; they key on the hardcoded RSA keys, which cannot change without splitting the network.
- Treat a Sality hit as a file-infector incident. EggJagger and any other payloads remain resident after the takedown, and every executable the host touched may be infected. Disinfect with a scanner that handles W32.Sality or reimage; do not simply delete the dropper.
- Check for the
amsint32service and for outbound connections to the nine URL-pack hosts, which will identify machines that were still fetching payloads at the end.
For OT and engineering environments
- Sality's 2022 delivery vector was "password recovery" tools for PLCs and HMIs, downloaded onto engineering workstations. Ban unofficial recovery utilities; route password recovery through the vendor.
- Air-gapped or USB-heavy environments are exactly where a file infector survives longest. Scan removable media on ingress.
For leadership
- This botnet ran for twenty-three years on a design that was fully published in 2011. It survived because file infection regenerates without effort and because decentralisation has no single point to seize. The end came only when a defender was willing to run the protocol at scale for months. Expect the same asymmetry against other legacy P2P families.
- The scale numbers in the press are not comparable to one another. When citing this operation, cite the figure with its source and date; the 15,000 figure has been withdrawn by its author, silently.
For the research community
- CrowdStrike edited a material figure in a primary technical write-up without a correction note. That practice makes the archived version, not the live one, the citable record. Capture snapshots of vendor disclosures at publication.
Sources
- US Department of Justice, USAO Central District of California. "Sality Malware Disrupted in International Cyber Takedown". 1 September 2026.
- CrowdStrike Counter Adversary Operations. "Peer Pressure: Inside the Sality Botnet Disruption Operation". 1 September 2026.
- Europol. "Global public-private operation disrupts Sality botnet active for two decades". 2 September 2026.
- Internet Archive. CrowdStrike post, snapshot of 2 September 2026 13:21 UTC ("over 15,000").
- Internet Archive. CrowdStrike post, snapshot of 4 September 2026 13:14 UTC ("over 33,000").
- Nicolas Falliere, Symantec Security Response. "Sality: Story of a Peer-to-Peer Viral Network" (mirror of the July 2011 whitepaper, v1.0).
- Dragos. "The Trojan Horse Malware & Password 'Cracking' Ecosystem Targeting Industrial Operators". 14 July 2022.
- US Department of Justice. "Justice Department Announces Actions to Dismantle Kelihos Botnet". 10 April 2017.
- US Department of Justice. "U.S. Leads Multi-National Action Against 'Gameover Zeus' Botnet and 'Cryptolocker' Ransomware, Charges Botnet Administrator". 2 June 2014.
- The Hacker News. "Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads". September 2026.
- Help Net Security. "Global sinkhole operation ends Sality botnet's 23-year run". 2 September 2026.
- BleepingComputer. "Sality botnet infrastructure dismantled in joint global takedown". September 2026.
- MITRE ATT&CK. T1685 Disable or Modify Tools; T1091; T1080; T1095; T1565.002. Accessed 11 September 2026.
Related Research
LockBit, BlackSuit and Play didn't run their own servers. They rented them from a company in St Petersburg that answered no abuse reports and no takedown requests, and billed like any other host.
A market that took only Monero ran for five years and €330 million. The playbook that broke Silk Road and AlphaBay did not apply — and the authorities who dismantled it have not said what did.
The malicious release carried valid SLSA provenance and passed every integrity check, because the honest build pipeline compiled source that was already poisoned. It also ran when a developer merely opened the folder.