# Global operation disrupts Sality P2P botnet

Published: 2026-09-02 · Severity: high
Canonical: https://vorant.io/reports/fe387fe5-af4e-5a93-b3f9-7a75c6e4c81e/global-operation-disrupts-sality-p2p-botnet

> International law enforcement took down the Sality peer-to-peer botnet, which infected over 11 million IP addresses across two decades.

On 31 August 2026, a coordinated international operation led by US authorities and supported by Europol disrupted the Sality peer-to-peer botnet, one of the most resilient criminal infrastructures in operation. The botnet had been active for more than 20 years and at its peak gave operators control of up to one million infected machines; over 11 million unique IP addresses have been linked to the infrastructure throughout its lifetime. Unlike traditional botnets relying on centralized command-and-control servers, Sality's decentralized peer-to-peer architecture made it particularly difficult to dismantle, as taking down individual nodes did not break the wider network.

The disruption was achieved through a coordinated sinkholing operation that redirected communications from infected machines away from the criminal infrastructure, rendering the operator's command channel inoperable. The operation involved law enforcement authorities from Bulgaria, Hungary, Romania, and the United States, coordinated by Europol's European Cybercrime Centre and supported by private-sector partners CrowdStrike and the Shadowserver Foundation. Europol had supported takedown efforts since 2017, with cooperation intensifying in the weeks before the final disruption through weekly operational calls.

Defenders should verify whether their networks contained infected systems linked to Sality's 11 million affected IP addresses and monitor for any remnant command-and-control communications. While the disruption has rendered the botnet's command infrastructure inoperable, devices that were previously compromised should be inspected for additional malware payloads that may have been distributed through the botnet before remediation.

## Mentioned in this report

- Malware: Sality

Source reporting: https://www.europol.europa.eu/media-press/newsroom/news/global-public-private-operation-disrupts-sality-botnet-active-for-two-decades

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/fe387fe5-af4e-5a93-b3f9-7a75c6e4c81e/global-operation-disrupts-sality-p2p-botnet.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
