Industry News

Long-Running Russian Botnet 'Sality' Dismantled After 20 Years

Reuters · 2 Sept 2026
Key Takeaway Regularly update and scan all business devices, since old malware like Sality can quietly persist on unpatched systems for years.

U.S. law enforcement officials, working alongside cybersecurity firm CrowdStrike, announced on Tuesday that they are dismantling Sality, a Russian cybercrime operation that has been running for roughly 20 years. Sality is one of the longest-running malware and botnet infrastructures known to researchers, historically used to infect computers worldwide and rope them into networks controlled by criminal operators.

While details of the operation remain limited, the takedown represents a significant milestone in international efforts to disrupt long-standing criminal infrastructure that has persisted despite years of security industry awareness. Botnets like Sality are typically used to distribute malware, send spam, conduct fraud, or provide a base for further attacks, often without victims realising their devices are compromised.

For small and medium businesses, the announcement is a reminder that older, seemingly forgotten malware families can remain active and dangerous for years if systems are not properly maintained. Ensuring devices are patched, running up-to-date security software, and monitoring for unusual network activity remains essential even against threats that predate current staff or IT setups.

Summarised by CISO AI from Reuters. We link back to every original so you can read it yourself.