U.S. DOJ-led Sality botnet takedown
Law Enforcement
Summary
Hide ▲
Show ▼
The U.S. Department of Justice and international partners carried out a coordinated Sality botnet takedown, using peer-to-peer sinkholing and domain seizures across the U.S. and Europe to disrupt the malware's control path. CrowdStrike said the botnet has been active since 2003 and has infected over 15,000 devices. The operation also isolated infected machines and blocked further payload delivery to the botnet's peers. CrowdStrike said the still-active networks were mainly used to push EggJagger payloads in clipjacking attacks.
Related Happenings
Sality botnet payload distribution and propagation activity
Malware Activity
H score62
First: 02.09.2026 09:56
Last: 02.09.2026 09:56
Sources 1
How related:
According to CrowdStrike, the botnet is said to have allowed the operator to distribute malicious payloads to more than 15,000 infected machines worldwide, adding that two independent P2P networks, known as version 3 and version 4, remained active until the disruption occurred.
About this happening:
The Sality botnet has operated since 2003 as a peer-to-peer (P2P) Windows malware network used to spread payloads and support credential theft, spam, proxy s...
Sality botnet payload distribution and propagation activity
Malware ActivityHow related: According to CrowdStrike, the botnet is said to have allowed the operator to distribute malicious payloads to more than 15,000 infected machines worldwide, adding that two independent P2P networks, known as version 3 and version 4, remained active until the disruption occurred.
About this happening: The Sality botnet has operated since 2003 as a peer-to-peer (P2P) Windows malware network used to spread payloads and support credential theft, spam, proxy s...
StealC and Amadey infostealer infrastructure disruption
Malware Activity
H score69
First: 24.06.2026 18:25
Last: 24.06.2026 18:25
Sources 1
About this happening:
StealC and Amadey malware infrastructure was disrupted in Operation Endgame, cutting off the command-and-control services used to manage infected systems. Europol said...
StealC and Amadey infostealer infrastructure disruption
Malware ActivityAbout this happening: StealC and Amadey malware infrastructure was disrupted in Operation Endgame, cutting off the command-and-control services used to manage infected systems. Europol said...
Foreign-run botnets relaying traffic through infected Canadian devices
Malware Activity
H score22
First: 22.06.2026 12:11
Last: 22.06.2026 12:11
Sources 1
About this happening:
The public ruling confirms two foreign-run botnets used infected Canadian devices as traffic relays, a setup that can conceal probing of critical infrastructure, governm...
Foreign-run botnets relaying traffic through infected Canadian devices
Malware ActivityAbout this happening: The public ruling confirms two foreign-run botnets used infected Canadian devices as traffic relays, a setup that can conceal probing of critical infrastructure, governm...
Operation Endgame international cybercrime disruption initiative
Public Sector Action
H score57
First: 19.06.2026 18:07
Last: 19.06.2026 18:07
Sources 1
About this happening:
Operation Endgame is an ongoing international law enforcement initiative that now includes the takedown of SocGholish infrastructure, expanding disruption of botnets a...
Operation Endgame international cybercrime disruption initiative
Public Sector ActionAbout this happening: Operation Endgame is an ongoing international law enforcement initiative that now includes the takedown of SocGholish infrastructure, expanding disruption of botnets a...
Vo1d botnet campaign targeting unofficial Android-based TV boxes
Campaign
H score88
First: 18.06.2026 20:37
Last: 18.06.2026 20:37
Sources 1
About this happening:
NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...
Vo1d botnet campaign targeting unofficial Android-based TV boxes
CampaignAbout this happening: NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...
Latest development: 03.07.2026 12:35
Google disabled all Google accounts used by NetNut for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing the compromised SDKs. The FBI’s seizure banner appeared on netnut.com while netnut.io briefly remained accessible, and Google said the coordinated actions caused significant degradation to NetNut’s proxy network and business operations.
Timeline
-
02.09.2026 09:56 3 articles · 2h ago
Authorities sinkhole the Sality P2P botnet and seize linked domains
Legal Policy Action UpdateOn August 31, 2026, authorities from the United States, Bulgaria, Hungary, and Romania, working with CrowdStrike and the Shadowserver Foundation, carried out a peer-to-peer sinkhole operation against the Sality botnet and seized Sality-linked domains in the U.S. and Europe. The action disrupted the botnet's P2P architecture, isolated peers from threat-actor control, and contributed to blocking further payload delivery to infected machines worldwide.
Show sources
- Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads — thehackernews.com — 02.09.2026 09:56
- Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads — thehackernews.com — 02.09.2026 09:56
- Sality botnet infrastructure dismantled in joint global takedown — www.bleepingcomputer.com — 02.09.2026 11:00
-
02.09.2026 09:56 1 articles · 2h ago
U.S. Department of Justice announces coordinated Sality botnet takedown
Initial DisclosureThe U.S. Department of Justice publicly announced the coordinated takedown of the Sality P2P botnet on Tuesday, describing a law-enforcement operation with CrowdStrike, the Shadowserver Foundation, and authorities from the United States, Bulgaria, Hungary, and Romania. The announcement said the effort used peer-to-peer sinkholing and domain seizures to neutralize Sality's control path and stop new payloads from reaching infected machines.
Show sources
- Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads — thehackernews.com — 02.09.2026 09:56