Security News

Decades-Old Sality Botnet Finally Taken Down

Security Week · 2 Sept 2026
Key Takeaway Regularly scan and patch older systems, as long-running botnets like Sality often persist on outdated machines that go unnoticed for years.

Sality, one of the oldest and most persistent malware families in existence, has been operating as a peer-to-peer (P2P) botnet for over two decades, infecting computers worldwide and using them to distribute further malicious software. According to SecurityWeek, security teams recently carried out a disruption operation targeting the botnet's infrastructure.

The takedown involved two key techniques: manipulating the botnet's peer lists, which infected machines use to communicate with one another, and removing the URLs hosting Sality's malicious payloads. Together, these actions cut off the botnet's ability to coordinate and spread further malware to compromised systems.

While the operation represents a significant step in dismantling long-running criminal infrastructure, botnets like Sality have shown resilience in the past, and remnants of infected machines may still exist. Businesses should not assume old threats are automatically gone, as legacy infections can persist quietly on outdated or unpatched systems for years.

botnet malware Sality threat-takedown network-security

Summarised by CISO AI from Security Week. We link back to every original so you can read it yourself.