International operation to disrupt the Sality botnet’s infrastructure

Posted date 10/09/2026

On 31 August 2026, an international operation was carried out targeting the infrastructure of the Sality botnet, a peer-to-peer network used for over two decades to distribute malicious payloads to compromised devices. The operation was led by US authorities and involved agencies from Bulgaria, Hungary and Romania, with the support of Europol, Eurojust and private companies specialising in cybersecurity. Sality had been active since at least 2003 and, according to Europol, at the height of its activity it could provide its operators with access to up to one million infected computers; over the years, more than 11 million unique IP addresses were associated with its infrastructure.

The operation targeted devices forming part of Sality’s P2P infrastructure and the domains used by the botnet. US authorities seized domains linked to Sality in the US, whilst authorities in Bulgaria, Hungary and Romania took action against additional infrastructure located in Europe. At the same time, CrowdStrike and the Shadowserver Foundation provided intelligence and technical analysis capabilities and carried out a P2P sinkholing operation, whereby communications from infected computers were redirected away from the criminal infrastructure. This action made it possible to isolate the compromised devices and render the communication channels used by the operator inoperative. Shadowserver also began collaborating with internet service providers and incident response teams to identify infected systems and facilitate the notification and remediation of victims.

According to information published by Europol and the participating agencies, the operation has succeeded in disrupting the Sality infrastructure and rendering its command-and-control channel inoperative; however, this does not mean that the malware has been automatically removed from all the computers that had been infected. The participating organisations are continuing their efforts to identify infections and facilitate the remediation of affected systems. Europol also notes that the operation is the result of several years of international cooperation and that, since 2017, it had been supporting the authorities in identifying and progressively dismantling components of the Sality infrastructure. Consequently, the officially reported status is that of a disrupted criminal infrastructure, with the computers that remained infected isolated from the operator’s infrastructure and with efforts to identify and remediate the victims still ongoing.
 

Etiquetas