A 23-year-old malware operation called Sality has just suffered one of its biggest setbacks.
On September 1, 2026, U.S. authorities, CrowdStrike and international law-enforcement agencies announced a coordinated operation to disrupt the Sality botnet, a sprawling network of infected computers that had survived for more than two decades. The operation involved authorities in the United States, Bulgaria, Hungary and Romania, alongside cybersecurity researchers and the Shadowserver Foundation.
But what made Sality so difficult to take down—and why did it survive for so long?
What Is the Sality Botnet?
Sality is a form of malware and botnet first observed in 2003. Over the years, it evolved from a conventional file-infecting malware into a sophisticated peer-to-peer (P2P) botnet.
Instead of depending on one central command server, infected computers could communicate directly with other infected machines. That decentralized structure meant there was no obvious single server that law enforcement could simply seize and shut down.
The compromised computers effectively became a hidden criminal network.
Operators could use the infrastructure to distribute additional malware and facilitate activities including cryptocurrency theft, spam, DDoS attacks, credential theft and proxy services.
Why Was Sality So Hard to Kill?
The key was its architecture.
Traditional botnets can have a central command-and-control server. Take that server offline and thousands of infected machines may lose their instructions.
Sality worked differently.
Its infected machines maintained lists of other peers and communicated across the network. That created redundancy: removing individual machines did not necessarily destroy the overall system.
CrowdStrike researchers describe this resilience as one of the main reasons Sality remained active for more than 20 years.
How Did the 2026 Sality Takedown Work?
The unusual part of the operation is that investigators turned Sality’s own architecture against it.
Rather than trying to contact every infected computer individually, CrowdStrike and partners carried out a peer-to-peer sinkhole operation.
Investigators manipulated the botnet’s peer-discovery process, gradually replacing legitimate peers with controlled sinkhole infrastructure. Infected machines that connected to those systems could then be isolated from the criminal network.
CrowdStrike says the operation ultimately affected a botnet involving more than 15,000 infected machines worldwide.
At the same time, the U.S. Justice Department and European partners seized Sality-linked domains used to distribute malicious files. Shadowserver is assisting internet providers and incident-response teams with identifying infections and notifying victims.
Is Sality Completely Gone?
Not necessarily.
The operation has disrupted the criminal control infrastructure, but that does not automatically mean every infected computer is clean.
The Justice Department specifically warned that compromised machines can still contain Sality malware and require remediation.
There is also another unanswered question: Will Sality’s operator rebuild?
The takedown demonstrates that even a decentralized botnet can eventually be disrupted. But cybercrime groups routinely adapt, rebuild infrastructure and change techniques after major disruptions.
Why the Sality Takedown Matters
The operation represents a broader shift in cybersecurity.
For years, defenders often focused on detecting malware after it entered a network. The Sality operation shows another strategy: attack the infrastructure that allows malware to remain useful.
The lesson is particularly important as modern cybercriminal networks become increasingly distributed.
Sality survived for more than two decades because decentralization made it difficult to dismantle. In 2026, that same architecture became the weakness investigators exploited.






