Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Government & Policy » US and European Police Dismantle Sality Botnet After More Than 20 Years

US and European Police Dismantle Sality Botnet After More Than 20 Years

Last updated:September 2, 2026
Human Written
  • Police in the US, Bulgaria, Hungary, and Romania teamed up to take down the Sality botnet.

  • The malware network has run since 2003 and helped steal cryptocurrency from victims worldwide.

  • CrowdStrike and the Shadowserver Foundation helped agents trick the botnet into cutting itself off.

US and European Police Dismantle Sality Botnet After More Than 20 Years

The Department of Justice announced a major win against cybercrime this week. Agents in the US worked with police in three European countries. Together, they took down a botnet called Sality. This network of infected computers has run since 2003. That makes it one of the oldest cybercrime tools still active today.

The FBI shared the news on X, saying the operation targeted a threat that has hurt victims both in the US and abroad. Private companies played a big role too, which shows how much law enforcement now depends on outside help to fight hackers.

Details of the Sality Takedown

The operation happened on August 31, 2026. Agencies in the US worked side by side with police in Bulgaria, Hungary, and Romania. Two private companies joined the effort as well. CrowdStrike and the Shadowserver Foundation brought their own tools and expertise to the table. Together, this group worked to knock out the botnet’s infrastructure for good.

Sality is not a small operation. It has infected more than 15,000 machines around the world. For years, it let its operator steal money and launch attacks on regular people and businesses. The malware often worked quietly, so most victims never even knew their computers were part of the problem. Owners of infected machines usually had no idea that hackers had turned their devices into hidden bots.

The main scheme in recent years centered on cryptocurrency theft. The malware watched a victim’s clipboard for crypto wallet addresses. Once it found one, it swapped it for the attacker’s own address instead. That trick alone earned the operator thousands of dollars from unsuspecting victims.

Investigators say the botnet also carried out other attacks, including spam campaigns and network break-ins. Reuters also reported that criminals used Sality for spamming, DDoS attacks, and cryptocurrency theft.

How the Sinkhole Operation Shut It Down

Sality worked differently than most botnets. Instead of relying on one central server, it used a peer-to-peer setup. That means every infected machine could talk directly to other infected machines nearby. This structure made older takedown methods much harder to pull off. Shutting down one server would not stop the whole network from working.

To counter this design, CrowdStrike’s team built a sinkhole. In simple terms, they fed the botnet false information. That false data tricked infected machines into cutting ties with the real operator. Once that link broke, the attacker lost control over the entire network. Agents call this kind of move a peer-to-peer sinkhole operation.

At the same time, officials worked to remove the botnet’s remaining paths back online. The Department of Justice, the FBI, and the Defense Criminal Investigative Service seized Sality-linked web domains inside the US. Police in Bulgaria, Hungary, and Romania seized more domains hosted across Europe. This step closed off any leftover ways the attacker might use to reach victims again.

Officials praised the joint effort behind the win. According to First Assistant United States Attorney Bill Essayli, threats like botnets and malware put both public safety and the economy at serious risk, and this result proves that government and private teams can win by working together.

Dutch authorities executed a similar infrastructure takedown in November 2025, dismantling a bulletproof hosting provider that had been linked to over 80 cybercrime cases worldwide since 2022. Officers seized approximately 250 physical servers from data centers in The Hague and Zoetermeer that had been used to facilitate ransomware attacks, botnets, phishing schemes, and the distribution of child sexual abuse material.

FBI Los Angeles Assistant Director Patrick Grandy added that this kind of teamwork boosts the FBI’s ability to fight cybercrime, and he promised more partnership work ahead to stop future attacks on people in the US.

Special Agent Kenneth DeChellis, who leads a cyber unit inside the Department of Defense, said guarding military networks against threats like Sality remains a top goal, and called this result proof of a long-standing bond between international police and private industry.

Advice for Anyone Who May Be Affected

The Shadowserver Foundation is not done yet. The group is now working with internet providers and cyber response teams around the world. Their goal is to find machines that are still infected. Once found, they plan to notify device owners and help walk them through cleanup steps.

If your computer feels slower than normal, that could be a warning sign. Run a full scan with trusted antivirus software right away. Update your operating system too, since old software often has gaps that malware can exploit. Also, avoid downloading files from sources you don’t fully trust.

Anyone who trades cryptocurrency should stay extra alert going forward. Malware like Sality often targets copied wallet addresses without any warning. Always double-check a wallet address before sending funds anywhere. Compare the address on your screen with the one you originally copied.

Watch your accounts closely over the next few weeks too. Report anything strange to your bank or crypto exchange right away. If your internet provider reaches out about a possible infection, don’t ignore that message. Follow their steps closely, since they may be trying to help clean your device.

This takedown shows a bigger trend in the fight against cybercrime. Police increasingly need private companies to help track and stop these networks. Botnets like Sality can run for decades if nobody steps in. This case proves that the right teamwork can shut down even old, stubborn threats.

Share this article

About the Author

Memchick E

Memchick E

Digital Privacy Journalist

Memchick is a digital privacy journalist who investigates how technology and policy impact personal freedom. Her work explores surveillance capitalism, encryption laws, and the real-world consequences of data leaks. She is driven by a mission to demystify digital rights and empower readers with the knowledge to protect their anonymity online.

View all posts by Memchick E >
Comments (0)

No comments.