hacker-news · Crawled Sep 2, 2026

Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads

21 IoCs 1 Malware
Read original article ↗

AI Summary

Authorities from the U.S., Bulgaria, Hungary, and Romania, in collaboration with CrowdStrike and the Shadowserver Foundation, disrupted the long-standing Sality peer-to-peer botnet on August 31, 2026. The operation used peer list manipulation to turn the botnet's P2P architecture against itself, sinkholing traffic and preventing infected machines from receiving new payloads. Sality, active since 2003, infects Windows executables and has delivered payloads like EggJagger, a clipper malware that steals cryptocurrency by replacing wallet addresses. While the disruption halts new payload delivery, existing infections remain active and require remediation.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 21 extracted

Type Value Detail
Domain forex2030[.]com Details →
Domain kharkovforum[.]com Details →
Domain avanchange Details →
Domain theunforgiven[.]p8[.]hu Details →
Domain painelwebradiodigital[.]awardspace[.]info Details →
Domain sgwebdesigner[.]free[.]fr Details →
Domain yonelco[.]com Details →
Domain pozdravizbeograda[.]com Details →
Domain highclass[.]atspace[.]com Details →
Domain situluimihai[.]3x[.]ro Details →
Domain gatheredovertime[.]com Details →
Domain imagebucket[.]biz Details →
IP 188[.]166[.]101[.]148 Details →
Filename top.gif Details →
Filename readme.pdf Details →
Filename left.gif Details →
Filename icon.png Details →
Filename styles.gif Details →
Filename top.png Details →
Filename nb4 Details →
Filename nv4 Details →

MITRE ATT&CK TTPs 5 techniques