Sality Botnet Takedown: 23-Year Malware Run Ends
Law enforcement, CrowdStrike, and the Shadowserver Foundation dismantled Sality, a Russia-linked P2P botnet that infected 11M+ devices over 23 years.
One of the internet’s longest-running malware operations has been shut down. On September 1–2, 2026, law enforcement agencies, CrowdStrike, and the Shadowserver Foundation announced they had dismantled Sality, a Russia-linked peer-to-peer botnet that had operated for 23 years and infected more than 11 million devices over its lifetime, according to reporting from CyberScoop, BleepingComputer, SecurityWeek, and The Register.
At the time of the takedown, more than 15,000 systems were still actively infected, the researchers said. The coordinated operation seized Sality’s command domains and, critically, broke the mechanism the botnet used to keep itself alive — rendering the network, in CrowdStrike’s words, effectively irrecoverable.
A 23-year survivor
Sality first appeared in 2003 and evolved over two decades into a resilient, self-propagating malware platform. Rather than relying on a small number of central command-and-control servers — the kind that are easy to seize and shut down — Sality was built as a peer-to-peer network. Each infected machine maintained a list of other infected peers, and the bots shared instructions and updates among themselves. That decentralized design is precisely why the botnet survived so long: with no single point of failure, taking down any handful of nodes did little to disrupt the whole.
Over its lifetime, Sality functioned as a general-purpose infection platform. It spread by infecting executable files and removable drives, disabled security software on compromised hosts, and served as a loader — a foothold that could pull down and run additional payloads, from spam modules to credential stealers. Its longevity made it a persistent piece of background noise on the global threat landscape, quietly recruiting machines that were often running outdated or unpatched software.
How the takedown worked
The decisive move targeted the very feature that made Sality durable: its peer list. Rather than trying to seize thousands of scattered nodes, CrowdStrike’s Counter Adversary Operations team ran a sinkhole operation that poisoned the data structure at the heart of every bot’s network awareness.
By injecting controlled entries into the peer-sharing mechanism, the operators were able to steer infected machines toward sinkhole servers under the responders’ control instead of toward other live bots. As the poisoned peer information propagated across the network — using Sality’s own gossip-style update system against it — bots progressively lost the ability to find one another and reach the operators. The Register described the approach as poisoning the network and diverting traffic into sinkholes; the effect was to sever the botnet’s internal connectivity from the inside out.
Alongside the technical disruption, a globally coordinated legal effort seized Sality’s domains. The operation was supported by the FBI and the U.S. Department of Justice, with participation from Europol and national authorities in Bulgaria, Hungary, and Romania. Shadowserver, which specializes in large-scale internet measurement and victim notification, said it is now working with internet service providers to identify the remaining infected devices and help with remediation.
Why peer-to-peer botnets are so hard to kill
Sality’s takedown is notable precisely because P2P botnets have historically resisted disruption. Centralized botnets funnel their bots to a known set of servers or domains; defenders can seize those, sinkhole the domains, and watch the network go dark. A well-segmented defensive posture and domain seizures are often enough to blunt that model.
Decentralized botnets flip the problem. There is no address to seize because the “server” is the swarm itself. Disrupting one requires either finding a flaw in the peer-discovery protocol or overwhelming it with attacker-controlled nodes — a technically demanding, sustained effort that has to reach a critical mass of the network before it takes hold. The Sality operation succeeded because responders understood the peer-list mechanism well enough to weaponize it, then executed the sinkhole at scale with legal cover to seize the supporting domains.
That combination — deep protocol knowledge plus international legal coordination — is the template that has taken down other resilient networks, and it is expensive to assemble. The 23-year gap between Sality’s emergence and its dismantling is a measure of just how hard the problem is.
A private-public model for takedowns
The operation also underscores how modern takedowns increasingly depend on private security firms working alongside governments. CrowdStrike supplied the technical capability to map and poison the peer network; Shadowserver is handling the unglamorous but essential work of victim identification and ISP outreach; and the FBI, DOJ, and European partners provided the legal authority to seize infrastructure across borders.
This blended model has become the norm for disrupting entrenched cybercrime operations, where the relevant telemetry and reverse-engineering expertise often sit inside vendors rather than agencies. It mirrors the way the security industry has responded to other large-scale threats, from ransomware campaigns abusing developer tooling to sprawling data-theft operations — incidents where no single organization holds all the pieces needed to respond.
What it means
Dismantling a 23-year-old botnet is a genuine win, but its practical impact should be read carefully. Sality was old, and many of the machines it infected were likely running legacy or poorly maintained software — the long tail of the internet where malware from the early 2000s can still find a home. Removing it clears real infection out of that population and denies the operators a durable loader platform.
Who wins. Defenders and, indirectly, the owners of the 15,000-plus still-infected machines, who now stand a chance of being notified and cleaned up through Shadowserver’s ISP outreach. The operation also demonstrates, again, that even decentralized botnets are not immune to disruption when responders invest the effort.
The limits. A takedown is not the same as prevention. The people behind Sality were not necessarily arrested, and the skills and infrastructure that sustain botnets remain widely available. Cleanup depends on ISPs and end users acting on notifications — a step that historically leaves a residue of infected devices online for years. Unlike a scored software vulnerability that can be tracked with a CVSS rating and patched on a schedule, an entrenched botnet is remediated one machine at a time.
What to watch. Whether the sinkhole holds and the remaining bots are successfully cleaned, whether any operators face charges, and whether the same peer-list poisoning technique gets turned against other resilient P2P networks. As offensive capabilities grow — including the AI-assisted cyber operations now drawing scrutiny across the industry — the defensive playbook demonstrated here, marrying vendor telemetry to cross-border legal action, is likely to be reused early and often.
Tagged
Keep reading
Chisato · · 4 min read What Is a Rootkit? Malware That Hides From the OS
A rootkit is malware that gains privileged access and then hides itself, and often other malware, from the operating system and security tools.
Chisato · · 4 min read ChocoPoC Malware Hides in Fake GitHub Exploit Code
A trojan called ChocoPoC hides in fake PoC exploit repos on GitHub, stealing browser passwords and cookies from security researchers. How the attack works.
Kurumi · · 6 min read AI Stocks Fall, Cybersecurity Rallies on Slowdown Calls
Chip and AI names sold off while CrowdStrike and Palo Alto surged after Amodei, Altman and Musk backed pacing frontier AI. Jensen Huang pushed back.