Inside the Takedown of Sality: A Long-Running Peer-to-Peer Botnet
Sality is one of the internet's longest-surviving malware families, known for infecting Windows systems and organising them into a decentralised, peer-to-peer botnet. Unlike botnets that rely on a central command server, Sality-infected machines communicate directly with each other, making the network resilient and harder to shut down using traditional takedown methods.
Researchers at CrowdStrike have published details on a disruption operation targeting this botnet, describing how threat hunting and intelligence techniques were used to map the network's peer-to-peer structure and undermine its operations. Because Sality has persisted for years and continues to infect vulnerable machines, understanding how it communicates and spreads is valuable for defenders trying to detect and remove it from their environments.
For small and medium businesses, the key concern is that older or unpatched Windows systems can still be silently recruited into botnets like Sality, often without obvious symptoms. Infected machines can be used for spam distribution, further malware delivery, or as launch points for other attacks, quietly consuming resources and putting business data at risk.