Decades-Old Sality Botnet Dismantled in Global Law Enforcement Operation
Law enforcement agencies from the US, Bulgaria, Hungary, and Romania, supported by Europol, CrowdStrike, and the Shadowserver Foundation, carried out a coordinated operation on August 31 to disrupt the Sality botnet. Unlike traditional botnets that rely on a central command server, Sality uses peer-to-peer communication between infected machines, making it notoriously difficult to take down. Authorities focused heavily on 'sinkholing' — redirecting infected machines' traffic away from the criminal network — while also seizing domains linked to the infrastructure.
According to Europol, Sality has been active for more than two decades and at its peak controlled over one million infected devices worldwide, with more than 11 million unique IP addresses linked to it over time. CrowdStrike said the botnet had been used to distribute malicious payloads to over 15,000 infected machines, enabling credential theft, spam distribution, proxy abuse, network exploitation, and DDoS attacks.
The operation reflects years of coordinated international effort, with Europol noting that cooperation between agencies intensified in the weeks before the takedown. The Shadowserver Foundation worked with internet service providers and national incident response teams to identify infections and help victims remediate compromised systems.