An international law enforcement operation led by authorities in the United States, with support from Europol, has dismantled the Sality peer-to-peer botnet after nearly two decades of illicit activity. The malicious infrastructure, which enabled criminal operators to distribute harmful payloads across compromised systems, has been linked by investigators to more than 11 million unique internet protocol addresses worldwide. Executed on August 31, 2026, the coordinated intervention brought together agencies from Bulgaria, Hungary, Romania, and the United States, alongside private cybersecurity specialists, to neutralise a network that gave cybercriminals control over as many as one million infected computers at its peak.
Decentralised Architecture Posed Prolonged Operational Challenge
Taking down the criminal operation required years of intelligence gathering because Sality functioned through a distributed peer-to-peer framework rather than a vulnerable centralised command server. In conventional architectures, disabling a primary control node halts criminal access, but Sality allowed infected systems to communicate directly with one another across borders. This resilient design enabled the botnet to persist even if individual segments went offline, requiring multinational agencies to track disparate technical components simultaneously. Europol had been assisting global partners in mapping Sality assets since 2017, culminating in weekly cross-border planning sessions leading up to the coordinated takedown across multiple European jurisdictions.
Sinkholing Technique Isolates Millions of Compromised Systems
To incapacitate the distributed network without needing to seize every infected terminal physically, investigators deployed an extensive peer-to-peer sinkholing manoeuvre. The technical procedure systematically intercepted and rerouted communications traveling from infected machines away from criminal controllers to safe destination servers managed by the coalition. By severing the communication pathway between the operators and the compromised hosts, the intervention rendered criminal command channels entirely inoperable. Europol confirmed that the redirection substantially degraded the operational capacity of the network, protecting compromised end-user devices from receiving further malicious instructions or additional attack payloads.
Multinational Coalition Combines Law Enforcement and Tech Sector
The strategic operation relied extensively on joint coordination between public justice systems and private cyber defenders collaborating through Europol’s Cyber Intelligence Extension Programme. Private industry partners CrowdStrike and the Shadowserver Foundation supplied specialised infrastructure intelligence and technical analysis to law enforcement teams. Operational meetings coordinated by Europol’s European Cybercrime Centre and the Joint Cybercrime Action Taskforce established an actionable operational overview among participating agencies, including Eurojust, Bulgaria’s General Directorate Combating Organised Crime, Hungary’s National Bureau of Investigation Cybercrime Department, Romania’s National Police, the United States Department of Justice, the Federal Bureau of Investigation, and the Defense Criminal Investigative Service.