hacker-news · Crawled Sep 2, 2026
Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads
21 IoCs 1 Malware
Read original article ↗
AI Summary
Authorities from the U.S., Bulgaria, Hungary, and Romania, in collaboration with CrowdStrike and the Shadowserver Foundation, disrupted the long-standing Sality peer-to-peer botnet on August 31, 2026. The operation used peer list manipulation to turn the botnet's P2P architecture against itself, sinkholing traffic and preventing infected machines from receiving new payloads. Sality, active since 2003, infects Windows executables and has delivered payloads like EggJagger, a clipper malware that steals cryptocurrency by replacing wallet addresses. While the disruption halts new payload delivery, existing infections remain active and require remediation.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 21 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | forex2030[.]com | Details → |
| Domain | kharkovforum[.]com | Details → |
| Domain | avanchange | Details → |
| Domain | theunforgiven[.]p8[.]hu | Details → |
| Domain | painelwebradiodigital[.]awardspace[.]info | Details → |
| Domain | sgwebdesigner[.]free[.]fr | Details → |
| Domain | yonelco[.]com | Details → |
| Domain | pozdravizbeograda[.]com | Details → |
| Domain | highclass[.]atspace[.]com | Details → |
| Domain | situluimihai[.]3x[.]ro | Details → |
| Domain | gatheredovertime[.]com | Details → |
| Domain | imagebucket[.]biz | Details → |
| IP | 188[.]166[.]101[.]148 | Details → |
| Filename | top.gif | Details → |
| Filename | readme.pdf | Details → |
| Filename | left.gif | Details → |
| Filename | icon.png | Details → |
| Filename | styles.gif | Details → |
| Filename | top.png | Details → |
| Filename | nb4 | Details → |
| Filename | nv4 | Details → |