US and European authorities, including the Romanian Police, have disrupted the peer-to-peer infrastructure used by the Sality botnet. The coordinated operation took place on August 31, 2026, with support from Europol, Eurojust, CrowdStrike and the Shadowserver Foundation. US authorities seized linked domains, while partners in Romania, Bulgaria and Hungary acted against infrastructure hosted in Europe.
The disruption cuts infected machines off from new tasking and payload delivery. It does not remove malicious code already present on those machines, restore damaged files or prove that credentials used from an infected endpoint remain private. Organizations that identify Sality activity still have an endpoint-integrity and account-recovery incident.
What the operation confirmed
The US Department of Justice says Sality has operated since 2003 and has enabled cryptocurrency theft and cyberattacks in the United States and abroad. Unlike a conventional botnet with a central command server, its infected systems exchanged peer lists and tasking directly. That design allowed the network to survive infrastructure removals for more than two decades.
CrowdStrike says the two active Sality networks could deliver additional payloads to more than 15,000 infected machines. The disruption manipulated their peer lists, inserted defender-controlled sinkholes and removed current payload URLs. CrowdStrike assesses that the operator can no longer communicate with those machines. Shadowserver is working with internet providers and incident-response teams to identify infections and notify victims.
Sality is also a polymorphic file infector. It can attach itself to executable files and spread through network shares, removable media and file sharing. CrowdStrike reports that the botnet delivered payloads associated with credential theft, proxy services, spam, exploitation and denial-of-service activity. Its main payload in recent years monitored clipboards and replaced cryptocurrency wallet addresses with attacker-controlled values.
A disabled botnet is not a clean endpoint
Sinkholing changes where infected machines communicate; it does not reverse every action performed before the disruption. A host may still contain infected executables, secondary malware, persistence or credentials exposed to processes that ran under the user or system context. Previous payloads may also have created access that does not depend on Sality's current peer-to-peer network.
Responders should therefore separate three conclusions: the operator's command path has been disrupted, a particular endpoint is infected, and a particular account or secret was exposed. The first is confirmed globally. The second and third require organization-level evidence.
Recover endpoint and credential trust in the right order
- Identify and isolate affected systems. Use the current CrowdStrike and Shadowserver guidance, endpoint telemetry and network logs to find systems contacting the sinkhole or known Sality infrastructure.
- Preserve evidence before cleanup. Capture volatile data, process history, network activity, authentication events and copies of suspicious executables needed for investigation.
- Scope secondary payloads. Determine what Sality delivered before the takedown and whether the endpoint shows credential theft, proxying, remote access or lateral movement.
- Rebuild when integrity cannot be established. A file-infector can contaminate executables across the system. Reimage from known-good media instead of assuming that deleting one file restores trust.
- Map secrets by reachability. Include browser sessions, password-manager access, service credentials, API keys, SSH material, recovery codes, cryptocurrency wallets and credentials used on the device during the exposure window.
- Revoke before replacing. Terminate active sessions, disable exposed tokens and invalidate old recovery material so attackers cannot retain access during rotation.
- Generate replacements from a clean environment. Use separately verified devices and identities, then rotate high-impact identity and recovery authorities before dependent accounts.
- Monitor for access outside Sality. Confirm that replacement credentials are not used from unexpected locations and that no alternate persistence remains.
Keep recovery values outside the suspected channel
A replacement password or recovery code should not be pasted into an email, chat or case transcript accessible from the infected endpoint. Verify the recipient independently and record authorization without recording the plaintext value. The receiving device must be known clean before the value is opened.
Secretus can deliver a replacement credential through a one-time link after the response team has established clean endpoints and identities. It reduces the durable plaintext retained in collaboration systems; it cannot disinfect a device, remove Sality or protect a value displayed on a compromised screen.
What remains unknown
Public reporting does not identify every infected organization, every secondary payload delivered or the credentials and data accessed on individual machines. Historical counts of Sality-linked IP addresses are not a current victim count. It is also too early to conclude that every infection has been remediated merely because the peer-to-peer command channel is no longer controlled by the operator.
Sources
- US Department of Justice: Sality malware disrupted in an international cyber takedown
- Europol: global public-private operation disrupts Sality
- CrowdStrike: technical account, infection identification and remediation guidance
- The Record: independent reporting on the disruption and remaining infected machines
- BleepingComputer: independent reporting on the international operation
