Skip to content
feed: live
>_0dayNews
threat intel

Sality Botnet Takedown: DOJ Seizes P2P Network

DOJ and international partners dismantled the Sality botnet by turning its own P2P relay infrastructure against itself. Infected Windows endpoints remain in the wild.

Sality Botnet Takedown: DOJ Seizes P2P Network
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
fuseMarisol "Fuse" Delgado·Published ·2 min read

The Sality botnet is down. The U.S. Department of Justice announced Tuesday that an international law enforcement operation, carried out alongside private-sector partners, seized Sality’s peer-to-peer relay infrastructure and cut off new payload delivery.

The mechanism was straightforward in concept: law enforcement turned the P2P network against itself. Sality used a distributed relay architecture rather than centralized command servers, which made it resilient to traditional takedowns. There was no single server to seize. Authorities instead poisoned the relay layer, using the botnet’s own P2P connectivity to prevent nodes from delivering new payloads or receiving updated commands. Infrastructure is now seized. The coordination capability is gone.

What Sality Was

Sality is a Windows file infector. It spread by attaching itself to legitimate executable files on compromised machines, writing copies into .exe files that users or automated processes might later run. That persistence mechanism is what made it sticky: removing Sality isn’t just deleting a process, it’s finding and cleaning every binary it wrote itself into. Miss one and it re-establishes from the next execution.

The P2P architecture meant every infected machine doubled as a relay. That design is why the botnet lasted as long as it did. It also meant that a coordinated sinkhole or relay-poisoning approach was the realistic path to disruption. That’s what happened here.

The Gap: Infected Endpoints Are Still Out There

Infrastructure seizure disrupts coordination. It doesn’t clean endpoints.

Machines that ran Sality before this takedown still have it. They can no longer receive new commands or updated payloads, but they still carry the infection. File infectors that wrote into executables on those systems remain. Law enforcement actions like this typically pair with coordinated victim notification through ISPs and updated AV signatures from security vendors.

If you have Windows systems in your environment that haven’t been scanned with current endpoint protection recently, check them. Sality has been detectable by major AV and EDR platforms for years. If your endpoint security is current and healthy, you’re likely covered. If you’re running legacy Windows machines with outdated or absent endpoint protection, this is the prompt to look.

Focus cleanup on machines that were isolated, air-gapped, or offline during prior AV campaigns: those are the ones most likely to still carry old infections. Standard file-integrity scanning will surface compromised executables.

Context

This is the second significant DOJ-backed cyber disruption operation in the past week. The FBI and DOJ dismantled the QTFY China espionage platform on August 27, and INTERPOL’s Jackal IV operation arrested 58 individuals tied to West African cybercrime networks the day before that. The pace of coordinated international actions is notable.

The Sality infrastructure seizure is substantive: a P2P botnet without a C2 backbone is effectively defanged. The remaining work is cleanup at the endpoint level, and that falls to defenders and AV vendors rather than law enforcement.

Sources: BleepingComputer, The Hacker News.

Found this useful? Share it.