Long-Running Sality Botnet Dismantled in Global Law Enforcement Operation
The U.S. Department of Justice has announced the takedown of Sality, a long-standing peer-to-peer botnet that has infected computers worldwide for years. The coordinated operation, carried out on August 31, 2026, involved law enforcement agencies from the United States, Bulgaria, Hungary, and Romania, alongside private-sector partners CrowdStrike and the Shadowserver Foundation.
Unlike traditional botnets that rely on centralised command-and-control servers, Sality used a peer-to-peer structure, allowing infected machines to communicate directly with each other and distribute new malware payloads without a single point of failure. This design has historically made Sality resilient and difficult to shut down. Investigators reportedly exploited the botnet's own P2P communication mechanism to disrupt its ability to deliver further malicious payloads to infected devices, effectively cutting off the network from receiving new instructions.
While the full technical details of the operation have not been disclosed, the takedown represents a significant win against a malware family that has persisted for years, infecting machines and potentially enabling further compromise or fraud. Businesses that may have older or unpatched systems remain at risk from residual infections or similar peer-to-peer threats.