Security News

Decades-Old Sality Botnet Dismantled in Global Law Enforcement Operation

Infosecurity Magazine · 3 Sept 2026
Key Takeaway Regularly patch and monitor older systems for signs of persistent malware infections, as long-running botnets like Sality can silently compromise devices for years without detection.

Law enforcement agencies from the US, Bulgaria, Hungary, and Romania, supported by Europol, CrowdStrike, and the Shadowserver Foundation, carried out a coordinated operation on August 31 to disrupt the Sality botnet. Unlike traditional botnets that rely on a central command server, Sality uses peer-to-peer communication between infected machines, making it notoriously difficult to take down. Authorities focused heavily on 'sinkholing' — redirecting infected machines' traffic away from the criminal network — while also seizing domains linked to the infrastructure.

According to Europol, Sality has been active for more than two decades and at its peak controlled over one million infected devices worldwide, with more than 11 million unique IP addresses linked to it over time. CrowdStrike said the botnet had been used to distribute malicious payloads to over 15,000 infected machines, enabling credential theft, spam distribution, proxy abuse, network exploitation, and DDoS attacks.

The operation reflects years of coordinated international effort, with Europol noting that cooperation between agencies intensified in the weeks before the takedown. The Shadowserver Foundation worked with internet service providers and national incident response teams to identify infections and help victims remediate compromised systems.

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.