The Good, the Bad and the Ugly in Cybersecurity – Week 36 (2026) The Good | Authorities Dismantle Sality Botnet & Charge Russian Serial Phisher A coordinated global takedown has successfully dismantled the long-standing Sality malware infrastructure and its associated domains in the U.S. and Europe. Between the DoJ, FBI, Europol, and Eurojust, the joint operation targeted the peer-to-peer (P2P) botnet that has been active since at least 2003. Operating out of Russia, the criminal group behind the botnet controlled over 15,000 infected devices worldwide. In recent years, Sality's primary payload was EggJagger, a stealthy clipjacking tool that hijacked cryptocurrency transactions by silently replacing wallet addresses. To neutralize the threat, cyber defenders turned Sality's P2P architecture against itself through protocol-level peer list manipulation, isolating infected hosts from the operators' command channels. While this massive sinkhole operation permanently blocks new payloads, the sinkholing doesn't remove malware already resident on infected machines and individual infections will persist until cleaned up. California’s federal grand jury has unsealed an indictment charging a Russian national for orchestrating a mass cyberespionage and phishing campaign targeting independent 80,000 freelancers. Authorities extradited Searzhudin Tamirlanovich Aktulaev to the U.S. following his arrest in Cyprus back in May 2025. Federal prosecutors allege that between June 2016 and November 2017, the defendant used 255 fake user accounts on a popular freelance platform to distribute malware-laced Excel files to unsuspecting workers. When opened, these attachments executed malicious macro commands that silently installed TVRAT and DarkVNC onto the victim endpoints. These remote access tools granted the attackers comprehensive control to harvest e-commerce credentials, private online passwords, and personally identifiable information (PII). Aktulaev currently remains in federal custody facing multiple serious charges, including wire fraud conspiracy, protected computer damage, and aggravated identity theft. The Bad | Iranian Threat Actors Pose as Recruiters to Deploy