Sality Botnet Dismantled After 23-Year Operation
A long-running Russia-based botnet known as Sality, which infected more than 15,000 devices worldwide over 23 years, was dismantled on September 1, 2026, in a coordinated international operation led by CrowdStrike and law enforcement agencies. The takedown severed the botnet operator's control over the infected machines, ending a persistent cybercriminal infrastructure that had evaded disruption for more than two decades. The operation was a joint effort involving the U.S. Department of Justice, the FBI, the Department of Defense Office of Inspector General's Defense Criminal Investigative Service, and the Shadowserver Foundation, with support from Europol, Eurojust, and law enforcement agencies in Bulgaria, Hungary, and Romania. Authorities seized domains in the United States and Europe that hosted the botnet's malware payloads, while CrowdStrike executed a technical sinkhole operation to isolate the peer-to-peer network. Sality first emerged in 2003 as a file-infecting virus that spread through executable programs on network shares and removable media.