Skip to Content
Join the Network with Us — Join Membership


International Crackdown on Sality Botnet, Active for Two Decades, Linked to More Than 11 Million Infected IP Addresses

September 3, 2026

An international law enforcement operation led by authorities in the United States, with support from Europol, has dismantled the Sality peer-to-peer botnet after nearly two decades of illicit activity. Investigators have linked the malicious infrastructure to more than 11 million unique IP addresses worldwide, with the network reportedly giving cybercriminals control over as many as one million infected computers at its peak.

A Coordinated Strike on August 31

Executed on August 31, 2026, the intervention brought together agencies from Bulgaria, Hungary, Romania, and the United States, alongside private cybersecurity specialists, to neutralise a network that had operated for roughly two decades. Given the sheer scale, more than 11 million distinct IP addresses linked to the botnet over its lifetime, this stands out as one of the more significant botnet takedowns of recent years.

Why This Network Took So Long to Dismantle

Taking down Sality required years of patient intelligence gathering, largely because of how the network was actually built. Unlike conventional botnets that rely on a centralised command server, disable that one node and the whole operation collapses, Sality operated through a distributed peer-to-peer framework, allowing infected systems to communicate directly with each other across borders. That resilient design meant the botnet could keep functioning even when individual segments went offline, forcing multinational agencies to track numerous disparate technical components simultaneously rather than targeting a single point of failure.

Europol had reportedly been assisting global partners in mapping Sality's assets since 2017, work that eventually culminated in weekly cross-border planning sessions ahead of the coordinated takedown across multiple European jurisdictions, nearly a decade of groundwork behind a single coordinated strike.

How the Botnet Was Actually Disabled

To incapacitate a network this distributed without needing to physically seize every single infected machine, investigators deployed an extensive peer-to-peer sinkholing operation. In practice, this meant systematically intercepting and rerouting communications travelling from infected machines away from the criminal operators and toward safe destination servers controlled by the coalition instead.

By severing the communication pathway between the actual operators and the compromised devices, the operation rendered the criminals' command channels entirely inoperable. Europol confirmed that this redirection substantially degraded the network's operational capacity, effectively protecting compromised end-user devices from receiving any further malicious instructions or additional attack payloads going forward.

A Genuine Public-Private Coalition

The operation leaned heavily on close coordination between public law enforcement and private cybersecurity firms, working together through Europol's Cyber Intelligence Extension Programme. Industry partners CrowdStrike and the Shadowserver Foundation supplied specialised infrastructure intelligence and technical analysis directly to law enforcement teams throughout the investigation.

Operational planning was coordinated through Europol's European Cybercrime Centre (EC3) and the Joint Cybercrime Action Taskforce (JCAT), which brought together a genuinely wide roster of agencies: Eurojust, Bulgaria's General Directorate Combating Organised Crime, Hungary's National Bureau of Investigation Cybercrime Department, Romania's National Police, the U.S. Department of Justice, the FBI, and the Defense Criminal Investigative Service, all working from a shared operational picture rather than acting independently.

FAQs

Q1. How many IP addresses were linked to the Sality botnet?

More than 11 million unique IP addresses worldwide, with the network controlling up to one million infected computers at its peak.

Q2. Why did Sality take so long to dismantle compared to other botnets?

Because it used a decentralised, peer-to-peer architecture rather than a single centralised command server, meaning it could keep functioning even if individual parts of the network went offline.

Q3. What technique did investigators use to disable the network?

A peer-to-peer sinkholing operation, intercepting and rerouting communications from infected machines away from the criminal operators to safe servers controlled by the investigating coalition.

Q4. Which agencies and organisations were involved in the takedown?

Law enforcement from the US, Bulgaria, Hungary, and Romania, alongside Europol's EC3 and JCAT, Eurojust, the FBI, the Defense Criminal Investigative Service, and private firms CrowdStrike and the Shadowserver Foundation.

in News
Share this post
Archive