Threat Intelligence

Long-Running Sality Botnet Dismantled in Global Law Enforcement Operation

The Hacker News · 2 Sept 2026
Key Takeaway Ensure all business devices are regularly updated and scanned for malware, as older infections like Sality can linger silently on unpatched systems for years.

The U.S. Department of Justice has announced the takedown of Sality, a long-standing peer-to-peer botnet that has infected computers worldwide for years. The coordinated operation, carried out on August 31, 2026, involved law enforcement agencies from the United States, Bulgaria, Hungary, and Romania, alongside private-sector partners CrowdStrike and the Shadowserver Foundation.

Unlike traditional botnets that rely on centralised command-and-control servers, Sality used a peer-to-peer structure, allowing infected machines to communicate directly with each other and distribute new malware payloads without a single point of failure. This design has historically made Sality resilient and difficult to shut down. Investigators reportedly exploited the botnet's own P2P communication mechanism to disrupt its ability to deliver further malicious payloads to infected devices, effectively cutting off the network from receiving new instructions.

While the full technical details of the operation have not been disclosed, the takedown represents a significant win against a malware family that has persisted for years, infecting machines and potentially enabling further compromise or fraud. Businesses that may have older or unpatched systems remain at risk from residual infections or similar peer-to-peer threats.

botnet malware law enforcement peer-to-peer cybersecurity takedown

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.