An international operation supported by Europol has disrupted Sality, a long-running peer-to-peer (P2P) botnet that has been used to spread malicious payloads to thousands of infected computers around the world.
The coordinated operation took place on August 31, 2026, and was led by US authorities. Investigators believe Sality had been operating for more than 20 years. At its peak, the botnet gave its operator access to as many as one million infected computers worldwide. More than 11 million unique IP addresses have been linked to its infrastructure over time.
Authorities from Bulgaria, Hungary, Romania and the United States took part in the operation, with support from Europol and private-sector cybersecurity groups CrowdStrike and the Shadowserver Foundation.
The operation used peer-to-peer sinkholing to redirect communications from infected computers away from the criminal infrastructure. This effectively separated compromised machines from the botnet and disabled the operator’s command channel.
Sality was particularly difficult to dismantle because it did not depend on a traditional central command-and-control server. Instead, infected computers communicated directly with each other, creating a decentralized network that could continue operating even when individual parts of the infrastructure were disrupted.
Europol has supported international efforts against Sality since 2017, helping law enforcement agencies identify and target different parts of the botnet across multiple countries. In the weeks before the latest operation, authorities and partners held weekly operational calls to coordinate their actions.
The disruption also relied heavily on cooperation between law enforcement and private cybersecurity organizations. Through Europol’s Cyber Intelligence Extension Programme, CrowdStrike and the Shadowserver Foundation provided technical expertise and infrastructure analysis.
Europol’s European Cybercrime Centre and Joint Cybercrime Action Taskforce helped coordinate intelligence sharing, operational meetings and analysis among the participating countries. This cooperation helped investigators build a clearer picture of Sality’s infrastructure and develop a coordinated plan to disrupt it.
Authorities involved included Bulgaria’s General Directorate Combating Organised Crime, Hungary’s National Bureau of Investigation Cybercrime Department, Romania’s National Police Directorate for Combating Organised Crime, and US agencies including the Department of Justice, Federal Bureau of Investigation and Defense Criminal Investigative Service. Europol and Eurojust also supported the operation.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
The action was carried out as part of EMPACT, the European Multidisciplinary Platform Against Criminal Threats, which brings together national authorities, EU institutions and international partners to tackle major organised and serious international crime threats.





