Feed›Malware›US and European authorities disrupt Sality botnet after 23 y...
MalwareCyber Insider
8.0 — CRITICAL

US and European authorities disrupt Sality botnet after 23 years

📅 2 September 2026 at 10:26 UTC📰 Cyber InsiderView original source ↗
US and European authorities disrupt Sality botnet after 23 years

US and European law enforcement agencies have disrupted the long-running Sality malware operation, cutting its operators off from more than 15,000 infected computers worldwide. The coordinated action, carried out on August 31, involved the US Department of Justice, FBI, Defense Criminal Investigative Service (DCIS), CrowdStrike, the Shadowserver Foundation, and Europol. CrowdStrike’s Counter Adversary Operations team … The post US and European authorities disrupt Sality botnet after 23 years appeared first on CyberInsider.

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

US and European authorities successfully disrupted the Sality botnet after 23 years, cutting off its operators from over 15,000 infected computers worldwide by exploiting a weakness in its peer-management protocol.

⚙️Technical Details
Affected Systems
Infected computers worldwide
Attack Vectors
Peer-to-peer sinkholing operationManipulation of Sality's own networking mechanism
💥Impact Assessment
Severity: High
Who Is at Risk
Organizations with infected systems, including those in the Arabic-language financial forum, Ukrainian web forum, and Russian cryptocurrency exchange.
🛡️Recommended Actions
1Scan systems for UDP connections to sinkhole address 188.166.101[.]148
2Review connections to disclosed payload URLs using published Sality v3 and v4 YARA rules
3Notify victims and take steps to remove malware already installed on compromised machines
📦Affected Products
Infected computers worldwide

Read the full article

This is a curated summary. The complete article is available at Cyber Insider.

Read on Cyber Insider ↗
← Back to feed