Sality’s Own Trust Model Enabled the Takedown

A joint law-enforcement and private-sector operation has disrupted Sality, the 23-year-old peer-to-peer botnet that had infected more than 15,000 machines and used to push payloads such as EggJagger and other malware. CrowdStrike and partners did it on Sept. 1 by sinkholing the network and removing super peers, while authorities also seized linked payload URLs. The key was Sality’s own peer trust. Its bots accepted peer lists without authentication, so the takedown team could feed them poisoned entries, knock out legitimate super peers, and steadily isolate infected hosts from operator control. That cuts off new payload delivery and coordination, but it does not clean the Windows machines already running Sality. For defenders, the lasting lesson is that a P2P botnet can be broken without seizing a central command server if its protocol can be manipulated. The exposure that remains is on the infected endpoints and any network that still has to find and clean them up.

Part of the PlainSec briefing for 2026-09-02

Editions

Sources