← Back to blog

Law Enforcement Disrupts Sality Botnet Using Its Own Network

A global operation has successfully disrupted the Sality P2P botnet by turning its infrastructure against itself. The takedown prevented new malware payloads from being distributed.

TL;DR

  • U.S. and international authorities disrupted the Sality botnet in a joint operation on Aug 31, 2026.
  • The takedown leveraged the botnet’s own P2P network to block distribution of new malware.
  • CrowdStrike and Shadowserver Foundation assisted in the technical disruption efforts.
  • Sality has been active for over a decade, infecting hundreds of thousands of systems.
  • This operation highlights the effectiveness of public-private partnerships in cyber defense.

In a significant win for cybersecurity, authorities from the U.S., Bulgaria, Hungary, and Romania have taken down the Sality botnet, a peer-to-peer network responsible for distributing malware across hundreds of thousands of devices. The operation, conducted on August 31, 2026, involved disrupting the botnet's communication channels by leveraging its own infrastructure.

Collaboration between government agencies and private sector firms like CrowdStrike and the Shadowserver Foundation enabled the technical disruption that cut off the delivery of new malicious payloads. This marks a major milestone in combating persistent threats through coordinated international action and innovative defensive strategies.

Operation Details

  • The takedown occurred on August 31, 2026, involving multiple countries including the U.S., Bulgaria, Hungary, and Romania.
  • Authorities used the botnet’s own P2P structure to disable command-and-control communications.
  • Private security firms CrowdStrike and Shadowserver played key roles in identifying and neutralizing the threat.

Impact and Significance

  • Sality has been operational for more than 10 years and infected an estimated hundreds of thousands of systems globally.
  • The disruption prevents further propagation of malware payloads via the compromised P2P network.
  • This case demonstrates how coordinated law enforcement and cybersecurity expertise can dismantle resilient botnets.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.