US-Led Operation Disrupts Long-Running Sality Botnet
An international operation led by U.S. authorities and cybersecurity firm CrowdStrike has disrupted the Sality botnet, a peer-to-peer network that has been active for more than two decades and was used primarily to steal cryptocurrency. The coordinated action, which took place on August 31, 2026, severed the connection between the alleged operators and over 15,000 infected computers worldwide. The U.S. Department of Justice announced the operation on September 2, 2026, detailing a multinational effort involving the FBI, the Defense Criminal Investigative Service, and law enforcement agencies from Bulgaria, Hungary, and Romania. Europol and Eurojust provided support, along with the nonprofit Shadowserver Foundation. The operation targeted the botnet's infrastructure, including the seizure of Sality-linked domains in the United States and Europe. Sality, first observed in 2003, evolved from a file-infecting virus into a resilient peer-to-peer botnet. Unlike traditional botnets that rely on a central command-and-control server, Sality's infected machines communicated directly with one another, making it exceptionally difficult to dismantle.