Sality Botnet Dismantled After 23 Years by Global Law Enforcement Effort
Authorities and cybersecurity firms have taken down the long-running Sality botnet, neutralizing its operations and preventing further cybercrime after infecting millions of computers worldwide.
By Isabel Navarro · First published 5 Sept 2026
In brief
- The Sality botnet, active since 2003, was one of the oldest and most persistent cybercrime networks.
- A coordinated operation involving the FBI, European agencies, CrowdStrike, and others successfully disrupted the botnet's infrastructure.
- Over 15,000 active infected systems were disconnected from Sality's control by manipulating its peer-to-peer communication.
- The takedown involved redirecting the network's connections and seizing control servers to neutralize ongoing threats.
- With the botnet now inactive, nonprofit groups are working to notify affected victims and prevent future exploitation.
Timeline · 7 moments
Sality botnet emerges, infecting computers worldwide
The Next Web ↗CrowdStrike and law enforcement begin coordinated disruption of Sality
Crowdstrike Blog ↗Authorities announce dismantling of Sality botnet after two decades
World News CNA ↗US Department of Justice confirms Sality takedown and infrastructure seizure
The Hacker News ↗Over 15,000 infected systems cut off from Sality control
The Register - Security ↗Action prevents further cryptocurrency theft by Sality operators
TechRadar ↗Nonprofits begin outreach to victims of Sality botnet
Cybersecurity Dive - Latest News ↗How it started
The Sality botnet first appeared in 2003, quickly evolving into one of the most resilient malware operations on the internet. It spread through infected files and removable drives, compromising millions of computers over its 23-year run. The botnet was primarily linked to Russian cybercriminals, who used it to deliver malware, steal data, and launch attacks globally.
Sality stood out for its use of a peer-to-peer architecture. This design made it difficult for authorities to target any single control point, helping the botnet survive multiple takedown attempts and security advances through the years.
How it unfolded
In late August 2026, cybersecurity firm CrowdStrike and international law enforcement agencies began a coordinated effort to disrupt Sality. According to Crowdstrike Blog, the operation targeted the botnet's trusted-peer protocol, which allowed infected computers to communicate and receive instructions.
On September 1, 2026, US officials and CrowdStrike announced that the botnet's infrastructure was being dismantled after two decades of activity, as reported by World News CNA. The operation redirected Sality's peer-to-peer network traffic to so-called 'sinkholes', effectively cutting communication between the botnet's operators and infected machines.
By September 2, 2026, the US Department of Justice confirmed the takedown, detailing how authorities had seized the malware's infrastructure and neutralized its ability to deliver new malicious payloads, according to The Hacker News. Private partners, including the Shadowserver Foundation, assisted in the technical aspects of the operation.
Further reports from The Register - Security and TechRadar noted that more than 15,000 infected endpoints were affected, and the action prevented further theft of cryptocurrency linked to Sality's activities.
By September 3, 2026, nonprofit groups were preparing to notify victims whose computers had been caught up in the botnet, as stated by Cybersecurity Dive.
Where it stands
The Sality botnet is no longer operational. Its peer-to-peer infrastructure has been dismantled, and infected computers have been disconnected from the network. Law enforcement and cybersecurity partners have seized control servers and redirected malicious traffic, effectively neutralizing the threat.
Efforts are now focused on outreach to affected victims, aiming to help them secure their systems and prevent reinfection. The operation is being hailed as a significant win against long-standing cybercrime.
What to watch
Nonprofit organizations and authorities are working to contact victims and help them clean up their systems. The long-term impact of the takedown will depend on how quickly users remove lingering infections and whether other botnets attempt to fill the void left by Sality.

