Global Public-private Operation Disrupts Sality Botnet Active for Two Decades
An international operation supported by Europol has disrupted the Sality peer-to-peer (P2P) botnet, a long-running criminal infrastructure used to distribute malicious payloads to thousands of infected computers worldwide.
The coordinated action, carried out on 31 August 2026 and led by the US authorities, targeted a botnet believed to have been operating for more than two decades. At its peak, the botnet gave its operator access to up to one million infected machines worldwide. To date, more than 11 million unique IP addresses have been linked to the infrastructure, which could be used to distribute malicious payloads to compromised devices.
The disruption activity brought together authorities from Bulgaria, Hungary, Romania, and the United States, with the support of Europol and private-sector partners CrowdStrike and the Shadowserver Foundation.
As part of the disruption, a peer-to-peer sinkholing operation was carried out to redirect communications from infected machines away from the criminal infrastructure. This isolated compromised devices from the botnet and rendered the operator’s command channel inoperable.
Disrupting one of the most resilient criminal infrastructures
Unlike botnets that rely on a traditional central command-and-control server, peer-to-peer botnets such as Sality use infected machines to communicate directly with one another. This decentralised structure makes them particularly resilient and difficult to dismantle, as disrupting individual parts of the infrastructure does not necessarily bring down the wider network.
Tackling Sality therefore required sustained international cooperation over several years. Since 2017, Europol has supported law enforcement authorities around the world in working together to identify and take down infrastructure linked to the botnet as different parts of the network were identified across jurisdictions.
In the weeks leading up to the latest disruption, this cooperation intensified, with partners holding weekly operational calls to coordinate their actions. Europol supported the involvement of law enforcement authorities in Bulgaria, Hungary and Romania, helping to coordinate measures against the botnet infrastructure across the different jurisdictions.
Public-private cooperation at the heart of the disruption
The disruption was made possible through close cooperation between law enforcement authorities and private-sector partners, bringing together cyber intelligence, investigative capabilities and technical expertise.
Through Europol’s Cyber Intelligence Extension Programme (CIEP), CrowdStrike and the Shadowserver Foundation worked alongside law enforcement authorities, providing technical expertise and infrastructure analysis in support of the disruption.
Europol’s European Cybercrime Centre (EC3) supported the exchange and analysis of cyber intelligence, and, together with the Joint Cybercrime Action Taskforce, organised operational meetings between all the partners involved. These efforts helped establish a common operational picture of the botnet and its infrastructure, facilitate intelligence sharing among the countries involved, and ultimately develop a coordinated disruption strategy.





