The US Department of Justice has announced a multinational operation to disrupt the Sality botnet, a malware network that has infected computers since 2003 and has been linked to cybercrime activities, including cryptocurrency theft and attacks targeting users in the US and other countries.
The operation involved law enforcement agencies from the US, Bulgaria, Hungary and Romania, along with cybersecurity companies CrowdStrike and the Shadowserver Foundation.
Authorities seized Sality-linked domains and carried out a peer-to-peer sinkhole operation aimed at disrupting the botnet’s infrastructure.
Algoritha Security Launches ‘Make in India’ Cyber Lab for Educational Institutions
What is the Sality malware network?
Sality operated as a decentralised peer-to-peer botnet, allowing infected computers to communicate with each other and share commands. Many device owners were reportedly unaware that their systems had been compromised and were being used as part of the malicious network.
The malware network had been active for several years and was used by cybercriminals to control infected devices and carry out harmful activities.
How authorities disrupted the botnet
The operation involved agencies including the FBI, the US Department of Defense Office of Inspector General’s Defense Criminal Investigative Service and the Justice Department.
European authorities also took action against additional domains linked to Sality. The Shadowserver Foundation worked with internet service providers and cybersecurity teams to identify infected devices and help affected users clean their systems.
Why Sality was a major cyber threat
The Sality botnet allowed attackers to control compromised computers without the knowledge of their owners. Such networks can be used to distribute malware, conduct cyberattacks and support other criminal activities.
US officials said the operation highlighted the importance of cooperation between government agencies and private cybersecurity companies in tackling cybercrime networks.
US expands focus on critical infrastructure security
The crackdown comes as the US continues efforts to strengthen protection against cyberattacks targeting critical infrastructure.
The administration recently launched “Project Watershed 250”, a six-month pilot programme aimed at protecting Texas-based water systems from cyber threats. The initiative brings together government agencies, cybersecurity companies and infrastructure operators to identify vulnerabilities before attackers can exploit them.
AI and cybersecurity efforts increase
The US Department of Defense is also expanding its use of artificial intelligence tools for cybersecurity and technology initiatives.
Government-focused AI services are being introduced to allow officials to use advanced AI models under security arrangements designed for government operations. The move aims to address concerns about handling sensitive information while improving cybersecurity capabilities.
Users should stay alert against malware threats
Cybersecurity experts recommend keeping systems updated, using security tools and avoiding suspicious downloads or links. Regular monitoring and timely security updates can help reduce the risk of devices becoming part of malware networks like Sality.
About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.