VORANT. Threat Intelligence Research Sign in Create a free account

Global operation disrupts Sality P2P botnet

high threat

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

International law enforcement took down the Sality peer-to-peer botnet, which infected over 11 million IP addresses across two decades.

On 31 August 2026, a coordinated international operation led by US authorities and supported by Europol disrupted the Sality peer-to-peer botnet, one of the most resilient criminal infrastructures in operation. The botnet had been active for more than 20 years and at its peak gave operators control of up to one million infected machines; over 11 million unique IP addresses have been linked to the infrastructure throughout its lifetime. Unlike traditional botnets relying on centralized command-and-control servers, Sality's decentralized peer-to-peer architecture made it particularly difficult to dismantle, as taking down individual nodes did not break the wider network.

The disruption was achieved through a coordinated sinkholing operation that redirected communications from infected machines away from the criminal infrastructure, rendering the operator's command channel inoperable. The operation involved law enforcement authorities from Bulgaria, Hungary, Romania, and the United States, coordinated by Europol's European Cybercrime Centre and supported by private-sector partners CrowdStrike and the Shadowserver Foundation. Europol had supported takedown efforts since 2017, with cooperation intensifying in the weeks before the final disruption through weekly operational calls.

Defenders should verify whether their networks contained infected systems linked to Sality's 11 million affected IP addresses and monitor for any remnant command-and-control communications. While the disruption has rendered the botnet's command infrastructure inoperable, devices that were previously compromised should be inspected for additional malware payloads that may have been distributed through the botnet before remediation.

Mentioned in this report

Malware Sality

Source reporting: https://www.europol.europa.eu/media-press/newsroom/news/global-public-private-operation-disrupts-sality-botnet-active-for-two-decades

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 10,768 reports from 152 sources, 472 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs