After more than two decades in operation, the Sality botnet has finally been dismantled in a sweeping international takedown. The U.S. Department of Justice confirmed that the botnet—a peer-to-peer malware network active since 2003—had been controlling over 15,000 infected systems globally. This operation involved agents in the United States, Bulgaria, Hungary, and Romania, working together to sever the botnet’s control and clean up the infrastructure it used.
Operation Overview
The effort was led by institutions including the DOJ, FBI, and the Defense Criminal Investigative Service (DCIS), partnered with private cybersecurity firms CrowdStrike and the Shadowserver Foundation. Their strategy centered on a technique known as peer-to-peer sinkholing, which rerouted botnet traffic away from the malicious controllers. Additionally, domain seizures in the U.S. and across Europe helped choke off Sality’s command channels.
Law enforcement from Bulgaria’s Organized Crime Directorate, Hungary’s National Bureau of Investigation Cybercrime Department, and Romania’s Central Cybercrime Unit, along with supranational groups Eurojust and Europol, mounted coordinated actions to take down Sality-related domains. Shadowserver is now collaborating with ISPs and national Computer Security Incident Response Teams to identify remaining compromised machines and support recovery for affected victims.
Why Sality Persisted—and What’s Next
Sality’s resilience stemmed from its decentralized peer-to-peer architecture. Instead of routing communications through a central server, infected machines exchanged commands directly, allowing the botnet to remain operational despite years of disruption efforts. Most owners of compromised systems were unaware their devices were part of the network.
The takedown marks one of the most significant campaigns against a P2P botnet in recent memory. It also reflects a broader shift in cybersecurity strategy: agencies are increasingly relying on intelligence from private firms in addition to traditional enforcement. The operation is being cited as an early example of a key tenet in national cyber strategy—‘shaping adversary behavior’ by targeting infrastructure and tools, not just actors.
At the time of disruption, more than 15,000 systems globally remained infected. The reaction now turns to remediation: identifying those systems, notifying owners, and removing the malware. Coordinated international effort ensures that cleanup extends beyond just seizing control points, but supports recovery too.
Analytical Angle: This takedown signals a landmark moment in cyber defense. It shows that even long-standing, resilient botnets can be dismantled when public and private sectors combine resources and expertise. It also highlights that architecture matters: decentralized networks can survive standard takedown tactics, making sinkholing and domain seizures essential tools. Going forward, success may depend on stronger global coordination, faster threat intelligence sharing, and devoting more resources to identifying infected machines before they fuel illicit operations like cryptocurrency thefts and distributed attacks.