Find notable cyber news and cases, enriched with sources, timelines, and signals.

U.S. DOJ-led Sality botnet takedown

Law Enforcement
First reported
Last updated
Happening score
H score 75
2 unique sources, 2 articles

Summary

Hide ▲

The U.S. Department of Justice and international partners carried out a coordinated Sality botnet takedown, using peer-to-peer sinkholing and domain seizures across the U.S. and Europe to disrupt the malware's control path. CrowdStrike said the botnet has been active since 2003 and has infected over 15,000 devices. The operation also isolated infected machines and blocked further payload delivery to the botnet's peers. CrowdStrike said the still-active networks were mainly used to push EggJagger payloads in clipjacking attacks.

Related Happenings

Sality botnet payload distribution and propagation activity

Malware Activity
H score62 First: 02.09.2026 09:56 Last: 02.09.2026 09:56 Sources 1

How related: According to CrowdStrike, the botnet is said to have allowed the operator to distribute malicious payloads to more than 15,000 infected machines worldwide, adding that two independent P2P networks, known as version 3 and version 4, remained active until the disruption occurred.

About this happening: The Sality botnet has operated since 2003 as a peer-to-peer (P2P) Windows malware network used to spread payloads and support credential theft, spam, proxy s...

StealC and Amadey infostealer infrastructure disruption

Malware Activity
H score69 First: 24.06.2026 18:25 Last: 24.06.2026 18:25 Sources 1

About this happening: StealC and Amadey malware infrastructure was disrupted in Operation Endgame, cutting off the command-and-control services used to manage infected systems. Europol said...

Foreign-run botnets relaying traffic through infected Canadian devices

Malware Activity
H score22 First: 22.06.2026 12:11 Last: 22.06.2026 12:11 Sources 1

About this happening: The public ruling confirms two foreign-run botnets used infected Canadian devices as traffic relays, a setup that can conceal probing of critical infrastructure, governm...

Operation Endgame international cybercrime disruption initiative

Public Sector Action
H score57 First: 19.06.2026 18:07 Last: 19.06.2026 18:07 Sources 1

About this happening: Operation Endgame is an ongoing international law enforcement initiative that now includes the takedown of SocGholish infrastructure, expanding disruption of botnets a...

Vo1d botnet campaign targeting unofficial Android-based TV boxes

Campaign
H score88 First: 18.06.2026 20:37 Last: 18.06.2026 20:37 Sources 1

About this happening: NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...

Latest development: 03.07.2026 12:35

Google disabled all Google accounts used by NetNut for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing the compromised SDKs. The FBI’s seizure banner appeared on netnut.com while netnut.io briefly remained accessible, and Google said the coordinated actions caused significant degradation to NetNut’s proxy network and business operations.

Timeline

  1. 02.09.2026 09:56 3 articles · 2h ago

    Authorities sinkhole the Sality P2P botnet and seize linked domains

    Legal Policy Action Update

    On August 31, 2026, authorities from the United States, Bulgaria, Hungary, and Romania, working with CrowdStrike and the Shadowserver Foundation, carried out a peer-to-peer sinkhole operation against the Sality botnet and seized Sality-linked domains in the U.S. and Europe. The action disrupted the botnet's P2P architecture, isolated peers from threat-actor control, and contributed to blocking further payload delivery to infected machines worldwide.

    Show sources
  2. 02.09.2026 09:56 1 articles · 2h ago

    U.S. Department of Justice announces coordinated Sality botnet takedown

    Initial Disclosure

    The U.S. Department of Justice publicly announced the coordinated takedown of the Sality P2P botnet on Tuesday, describing a law-enforcement operation with CrowdStrike, the Shadowserver Foundation, and authorities from the United States, Bulgaria, Hungary, and Romania. The announcement said the effort used peer-to-peer sinkholing and domain seizures to neutralize Sality's control path and stop new payloads from reaching infected machines.

    Show sources