Sality botnet taken down after 2 decades in service
Up to a million devices infected at its peak.

Computers. Image by Tempura/Getty Images
- Authorities disrupted the Sality botnet after more than 20 years of activity.
- Sality used infected devices to spread malware, steal cryptocurrency, and support cyberattacks worldwide.
- The operation redirected infected devices away from criminal infrastructure and seized Sality-linked domains.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Supported by Europol and Eurojust, law enforcement authorities have taken down Sality, a resilient peer-to-peer (P2P) botnet that operated for over 2 decades.
Sality, first observed in 2003, was a botnet used by cybercriminals to distribute malware to computers, enabling cryptocurrency theft and cyberattacks on victims worldwide.
Usually, botnets rely on a central command-and-control (C2) server to operate. However, P2P botnets like Sality use infected devices to communicate with one another, meaning there’s no central server to take down.
This decentralized infrastructure makes them particularly resilient and difficult to dismantle, as disrupting individual parts of the infrastructure doesn’t necessarily bring down the entire network.
Since 2017, Europol has been supporting law enforcement authorities in Bulgaria, Hungary, Romania, and the United States in identifying and taking down infrastructure linked to the Sality botnet.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
On August 31st, 2026, the authorities succeeded in taking down the botnet, which had operated for more than 20 years.
As part of the disruption, a P2P sinkholing operation was carried out. Simply put, all communications between infected devices were redirected away from the criminals’ infrastructure and isolated from the botnet operator.
“Once isolated, bots can no longer receive URL packs (payload download instructions) or file packs (direct payload transfers), rendering the botnet unable to carry out new tasking,” cybersecurity firm CrowdStrike, which was one of the private sector partners that participated in the operation, explains in a blog.
Furthermore, Sality-linked domains were seized.
“Cybercriminals, botnets, and malware are a clear and present danger to our nation’s security and economy. This successful effort to take down the Sality botnet shows that by working together, the public and private sectors can be a powerful force for good,” First Assistant US Attorney Bill Essayli said in a statement.
At its peak, the Sality botnet operator had access to up to a million infected devices worldwide.