Police Hijack Sality Botnet's Own Network to Kill It Off
A four-country operation used the malware's peer-to-peer design against it, blocking infected computers from receiving fresh criminal payloads.

Key points
- The U.S. Department of Justice announced the takedown of the Sality botnet on Tuesday, following a coordinated operation on August 31, 2026.
- Authorities from the United States, Bulgaria, Hungary and Romania ran the operation with help from CrowdStrike and the Shadowserver Foundation.
- Sality is a peer-to-peer botnet, meaning infected PCs pass instructions to each other rather than relying on a central server.
- Investigators turned that same peer-to-peer design against the network to stop new malware reaching infected machines.
- Owners of infected Windows computers should run a full antivirus scan and install pending updates.
Police have pulled the plug on Sality, one of the internet's longest-running networks of hijacked Windows computers.
The U.S. Department of Justice announced the takedown on Tuesday. It was carried out on August 31, 2026, alongside law enforcement in Bulgaria, Hungary and Romania. Two private firms helped: the security company CrowdStrike and the non-profit Shadowserver Foundation, which tracks infected machines around the world.
Sality has been active for well over a decade. It is what security researchers call a botnet: a large group of computers that have been quietly infected with malicious software and can be controlled from afar by criminals. Owners usually have no idea their PC is part of one.
What is Sality and why did it last so long?
Sality is a peer-to-peer botnet, which means the infected computers talk directly to each other instead of checking in with one central website. That design is what kept it alive for so long. There was no single server the police could seize to shut it down.
Most older botnets used a command-and-control server, a single machine that hands out instructions. Knock that server offline and the whole network goes dark. Sality did not work that way. Each infected PC could pass new commands and new malware to its neighbours, so the network healed itself whenever pieces were removed.
That is also why criminals liked renting access to it. A Sality infection was often the first foothold, later used to drop other nasties: banking trojans that steal online banking logins, ransomware that locks files until a payment is made, and password stealers.
How did police finally take it down?
Investigators used the botnet's peer-to-peer design against it. Rather than trying to find a central server that did not exist, they fed the network their own instructions through the same channels the criminals used, cutting infected computers off from any new malware payloads.
In plain terms, the police joined the gossip circle and started spreading a message that quietly muzzled it. Infected machines can no longer be given fresh jobs by the gang that ran them.
According to reporting from The Hacker News, the coordinated action drew on months of tracking by CrowdStrike and Shadowserver, who mapped which computers were talking to which. That map is what made a surgical takedown possible.
| Detail | Value |
|---|---|
| Operation date | August 31, 2026 |
| Announced by | U.S. Department of Justice |
| Countries involved | U.S., Bulgaria, Hungary, Romania |
| Private partners | CrowdStrike, Shadowserver Foundation |
| Botnet type | Peer-to-peer |
What should ordinary computer users do?
If you use a Windows PC, run a full scan with your antivirus and install any pending Windows updates. Sality mainly spread through infected USB sticks and pirated software downloads, so it tended to sit on older, unpatched home machines for years.
Shadowserver typically shares lists of infected internet addresses with national response teams, so your internet provider may contact you if your home network was involved. A takedown does not remove the malware from your computer; it only stops the criminals from sending it new orders. Cleaning the machine is still on you.
A quick honesty note on authentication, since it is my beat: multi-factor authentication would not have prevented a Sality infection, because the malware spread through files, not stolen logins. What it does help with is the follow-on damage, stopping criminals from reusing any passwords the malware scraped off your PC.



