# Europol dismantles Sality botnet after 20 years

Published: 2026-09-02 · Severity: routine
Canonical: https://vorant.io/reports/fe387fe5-af4e-5a93-b3f9-7a75c6e4c81e/europol-dismantles-sality-botnet-after-20-years

> Europol coordinated a public-private operation that disrupted the long-running Sality botnet, which had been active for roughly two decades.

Europol announced a coordinated law enforcement and private-sector operation that disrupted infrastructure associated with the Sality botnet, a polymorphic file-infecting malware family that has been active since the early 2000s. Sality has historically been used to build large peer-to-peer botnets capable of spam distribution, click fraud, credential theft, and further malware delivery, making it one of the longest-running malware operations tracked by security researchers and law enforcement.

The source page provided contains no substantive technical detail (it is a JavaScript-loading placeholder rather than the full article text), so specific indicators of compromise, affected infrastructure, victim counts, or named suspects are not available from this capture. Based on the title and known public reporting patterns for this type of Europol announcement, the action appears to be a takedown/disruption operation rather than a report of new active exploitation.

For defenders, this is primarily an informational item: organizations that may have historically encountered Sality infections (older Windows systems, unpatched legacy endpoints) should ensure AV/EDR signatures for Sality remain current and that any dormant infected hosts are identified and remediated, since disrupted botnet infrastructure can sometimes be reconstituted by residual infected endpoints reaching out to new command channels.

## Mentioned in this report

- Malware: Sality

Source reporting: https://www.europol.europa.eu/media-press/newsroom/news/global-public-private-operation-disrupts-sality-botnet-active-for-two-decades

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/fe387fe5-af4e-5a93-b3f9-7a75c6e4c81e/europol-dismantles-sality-botnet-after-20-years.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
