Skip to content
US takes down Sality malware network in global cyber crackdown as Trump administration ...

US takes down Sality malware network in global cyber crackdown as Trump administration ...

Firstpost September 2, 2026

The US Department of Justice has dismantled parts of the long-running Sality botnet in a multinational operation spanning the US, Bulgaria, Hungary and Romania. The move comes as Washington intensifies efforts to protect critical infrastructure and government systems, deploying artificial intelligence, cybersecurity tools and international partnerships against growing cyber threats.

The US Department of Justice has announced a multinational operation to disrupt the Sality botnet, a malware network that has infected computers since 2003 and been linked to cryptocurrency theft and cyberattacks targeting victims in the US and abroad.

The operation involved law enforcement agencies in the US, Bulgaria, Hungary and Romania, alongside private-sector cybersecurity firms CrowdStrike and the Shadowserver Foundation. Authorities seized Sality-linked domains and carried out a peer-to-peer sinkhole operation designed to disrupt the botnet's infrastructure.

US agencies involved included the FBI, the Department of Defense Office of Inspector General's Defense Criminal Investigative Service (DCIS) and the Justice Department. European authorities also seized or disrupted additional domains linked to Sality.

Sality operated as a decentralised peer-to-peer botnet, allowing compromised computers to communicate with one another and commands. Owners of infected devices were typically unaware that their computers had been taken over and were being used as part of the malicious network.

CrowdStrike's Counter Adversary Operations team worked with US and international authorities on Monday to execute the sinkhole operation. The Shadowserver Foundation is also working with internet service providers and computer security incident response teams to identify infected devices and help notify victims so that systems can be cleaned up.

The operation involved Bulgaria's General Directorate Combating Organised Crime, Hungary's National Bureau of Investigation Cybercrime Department and Romania's Police and Central Cybercrime Unit, with support from Eurojust and Europol.

US officials said the operation demonstrates the importance of cooperation between government agencies and private cybersecurity companies in disrupting cybercrime infrastructure.

The crackdown comes as the US has been working to strengthen its defences against cyberattacks targeting critical infrastructure. Just a day ago, the Trump administration launched “Project Watershed 250 ”, a six-month pilot programme aimed at protecting Texas-based water systems from cyberattacks.

The initiative brings federal, state and private-sector cybersecurity capabilities together to identify vulnerabilities in water infrastructure before hackers can exploit them. It will connect water utilities with US cybersecurity companies and use artificial intelligence tools to assess and strengthen existing defences.

The programme will also employ “red teaming” to simulate attacks and stress-test water utilities, helping identify weaknesses that could potentially be exploited by adversaries before defensive measures are put in place.

The Pentagon has also expanded its use of AI as part of its broader cybersecurity and technology push. The US Department of Defense is giving its civilian and military workforce access to customised versions of OpenAI's ChatGPT and xAI's Grok through its secure GenAI.mil platform.

The new services, ChatGPT Mil and Grok for Government, join Google's Gemini, which was initially available through the centralised portal. More than 1.7 million people have already used GenAI.mil, according to the Department of Defense, out of roughly 3 million civilian and military personnel.

The military-focused AI services are designed to allow government workers to use advanced models while operating under government-specific security arrangements, addressing concerns around the handling of potentially sensitive information on consumer AI platforms.

us takes down sality malware network in global cyber crackdown as trump administration steps up defences against attacks

Anthropic bets on lower costs and stronger coding with Claude Fable 5.1 and Mythos 5.1

Apple CEO John Ternus touts new products, teases ‘Phenomenal’ iPhone launch as he takes the helm

Perplexity launches Hybrid Compute to combine cloud and local AI for sensitive tasks

Firefox adds built-in ad blocker to iOS, giving users an easier way to block ads and trackers

Extracted Entities

Attack Types (1)

Campaigns (1)

Domains (1)

Industries (1)

Malware (1)