Sality botnet payload distribution and propagation activity
Malware Activity
Summary
Hide ▲
Show ▼
The Sality botnet has operated since 2003 as a peer-to-peer (P2P) Windows malware network used to spread payloads and support credential theft, spam, proxy services, network exploitation, and DDoS attacks. CrowdStrike said the botnet could distribute malicious payloads to more than 15,000 infected devices worldwide, and that its version 3 and version 4 P2P networks were still active before disruption. In 2026, the U.S. DOJ, FBI, and DCIS and partners in Bulgaria, Hungary, and Romania seized Sality-linked domains and used peer-to-peer sinkholing to isolate infected machines and cut off control channels. CrowdStrike said the operation ended the operator’s control of the botnet and disrupted its payload delivery infrastructure.
Related Happenings
U.S. DOJ-led Sality botnet takedown
Law Enforcement
H score75
First: 02.09.2026 09:56
Last: 02.09.2026 09:56
Sources 1
How related:
International law enforcement agencies and private partners have seized Sality malware infrastructure in a joint action aiming to disrupt and take down the peer-to-peer (P2P) botnet.
About this happening:
The U.S. Department of Justice and international partners carried out a coordinated Sality botnet takedown, using peer-to-peer sinkholing and domain seizures acros...
U.S. DOJ-led Sality botnet takedown
Law EnforcementHow related: International law enforcement agencies and private partners have seized Sality malware infrastructure in a joint action aiming to disrupt and take down the peer-to-peer (P2P) botnet.
About this happening: The U.S. Department of Justice and international partners carried out a coordinated Sality botnet takedown, using peer-to-peer sinkholing and domain seizures acros...
Millenium RAT Windows malware activity and native C++ rewrite
Malware Activity
H score62
First: 29.06.2026 17:30
Last: 29.06.2026 17:30
Sources 1
About this happening:
The Millenium RAT malware activity is spreading across Windows systems, with 60,000+ infections in 160+ countries and a newer native C++ build that helps it ev...
Millenium RAT Windows malware activity and native C++ rewrite
Malware ActivityAbout this happening: The Millenium RAT malware activity is spreading across Windows systems, with 60,000+ infections in 160+ countries and a newer native C++ build that helps it ev...
Foreign-run botnets relaying traffic through infected Canadian devices
Malware Activity
H score22
First: 22.06.2026 12:11
Last: 22.06.2026 12:11
Sources 1
About this happening:
The public ruling confirms two foreign-run botnets used infected Canadian devices as traffic relays, a setup that can conceal probing of critical infrastructure, governm...
Foreign-run botnets relaying traffic through infected Canadian devices
Malware ActivityAbout this happening: The public ruling confirms two foreign-run botnets used infected Canadian devices as traffic relays, a setup that can conceal probing of critical infrastructure, governm...
Operation Endgame international cybercrime disruption initiative
Public Sector Action
H score57
First: 19.06.2026 18:07
Last: 19.06.2026 18:07
Sources 1
About this happening:
Operation Endgame is an ongoing international law enforcement initiative that now includes the takedown of SocGholish infrastructure, expanding disruption of botnets a...
Operation Endgame international cybercrime disruption initiative
Public Sector ActionAbout this happening: Operation Endgame is an ongoing international law enforcement initiative that now includes the takedown of SocGholish infrastructure, expanding disruption of botnets a...
Vo1d botnet campaign targeting unofficial Android-based TV boxes
Campaign
H score88
First: 18.06.2026 20:37
Last: 18.06.2026 20:37
Sources 1
About this happening:
NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...
Vo1d botnet campaign targeting unofficial Android-based TV boxes
CampaignAbout this happening: NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...
Latest development: 03.07.2026 12:35
Google disabled all Google accounts used by NetNut for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing the compromised SDKs. The FBI’s seizure banner appeared on netnut.com while netnut.io briefly remained accessible, and Google said the coordinated actions caused significant degradation to NetNut’s proxy network and business operations.
Timeline
-
02.09.2026 09:56 1 articles · 2h ago
U.S. and partner authorities sinkhole the Sality botnet and seize linked domains
Legal Policy Action UpdateAuthorities from the U.S., Bulgaria, Hungary, and Romania, working with CrowdStrike and the Shadowserver Foundation, used peer-to-peer sinkholing to disrupt the Sality P2P botnet and seized Sality-linked domains in the U.S. and Europe, cutting off the botnet's control infrastructure.
Show sources
- Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads — thehackernews.com — 02.09.2026 09:56
-
02.09.2026 09:56 3 articles · 2h ago
CrowdStrike says Sality reached more than 15,000 infected machines
Campaign Scope UpdateCrowdStrike said the Sality botnet allowed operators to distribute malicious payloads to more than 15,000 infected machines worldwide, and that its version 3 and version 4 peer-to-peer networks remained active until the disruption.
Show sources
- Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads — thehackernews.com — 02.09.2026 09:56
- Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads — thehackernews.com — 02.09.2026 09:56
- Sality botnet infrastructure dismantled in joint global takedown — www.bleepingcomputer.com — 02.09.2026 11:00