Threat Intel
CrowdStrike & Partners Strike Down Sality Botnet in Coordinated Disruption
In a joint effort with international law‑enforcement agencies and industry allies, CrowdStrike executed the “Peer Pressure” operation to dismantle the Sality peer‑to‑peer botnet. The campaign severed command‑and‑control channels, seized malicious infrastructure, and disrupted the botnet’s ability to distribute ransomware and other payloads. The takedown removes a key threat vector that has infected millions of hosts worldwide, demonstrating the power of coordinated cyber‑defense operations.
On September 1, 2026, CrowdStrike announced the successful execution of the "Peer Pressure" operation, a coordinated effort that brought the Sality peer‑to‑peer botnet to a halt. By working hand‑in‑hand with law‑enforcement agencies and industry partners, the team was able to sever the botnet’s command‑and‑control infrastructure, seize malicious domains, and disrupt its ability to spread malware.
Why Sality Matters
Salient for its resilience and stealth, Sality has been a persistent threat since 2017. The botnet’s decentralized architecture makes it difficult to take down, yet it has been responsible for the delivery of ransomware, data‑exfiltration tools, and other malicious payloads to millions of infected machines across the globe.
The Disruption Playbook
- Coordinated takedown: Joint operations with international law‑enforcement agencies ensured synchronized actions against key infrastructure nodes.
- Infrastructure seizure: Malicious domains and hosting services were seized, cutting off the botnet’s communication backbone.
- Threat intelligence sharing: Real‑time data was shared with industry partners, allowing them to patch vulnerabilities and block malicious IPs.
- Legal enforcement: Arrest warrants were issued for operators behind the Sality network, adding a deterrent layer to future attacks.
Impact on the Threat Landscape
The disruption removed a major vector for ransomware and data‑exfiltration campaigns. Early post‑operation analysis indicates a significant drop in new infection rates and a halt in the botnet’s ability to propagate.
"The success of Peer Pressure underscores the effectiveness of coordinated cyber‑defense, blending technical disruption with legal action to neutralize a long‑standing threat," said a CrowdStrike spokesperson.
Key Takeaways for Defenders
- Invest in threat‑intelligence feeds that can quickly identify botnet infrastructure.
- Collaborate with law‑enforcement to ensure swift takedown of malicious assets.
- Maintain robust network segmentation to limit the spread of peer‑to‑peer malware.
- Leverage automated response workflows to isolate infected hosts before they can communicate with command‑and‑control servers.