Sality Botnet Dismantled After 23 Years and 11 Million Infections
Authorities have disrupted the Russia‑based Sality botnet, a peer‑to‑peer malware network active since 2003 that infected around 11 million devices and enabled cryptocurrency theft and other cyberattacks.
An international law enforcement operation has dismantled the Sality botnet, a long‑running malware network that infected millions of devices worldwide and supported a range of cybercrimes.
Sality, based in Russia, had been active since 2003. It used a peer‑to‑peer design, meaning infected machines communicated directly with each other rather than through a single central server. Over time, it compromised about 11 million devices.
CrowdStrike, the FBI, Europol and authorities in Bulgaria, Hungary and Romania worked together on the takedown. Instead of seizing a central command server, they targeted the peer lists on infected computers — the data that tells compromised machines how to find and talk to other bots. By disrupting those connections, they cut the network off from its operators.
The botnet was used to steal cryptocurrency and to launch other cyberattacks against its victims. For individual users and small organisations, infection often meant slower systems and hidden loss of data or digital money.
Removing Sality from the internet deprives its controllers of a powerful tool they had refined over more than two decades. It also shows that even decentralised, long‑lived criminal networks can be disrupted when private companies and cross‑border law enforcement work together.
Key signs to watch now are whether variants of Sality reappear under a different name, whether similar peer‑to‑peer botnets are targeted next, and how quickly criminals shift to other infrastructures.
Sources
- OSINT