Destruction of Sality Botnet: A Major Cybersecurity Milestone

Destruction of Sality Botnet: A Major Cybersecurity Milestone

First seen 3 Sep 2026, 18:58 UTC www.euronews.rowww.digi24.ronewsweek.ro 34.0

Article Content

Browse articles
ThreatCluster

On August 31, 2026, an international operation led by the FBI dismantled the Sality botnet, active for over 20 years. Romania, along with the U.S., Bulgaria, and Hungary, played a crucial role in this operation. Sality was responsible for infecting millions of computers worldwide, with over 11 million unique IP addresses linked to its infrastructure. The botnet was utilized for various cybercrimes, including cryptocurrency theft and spam distribution. Authorities confiscated domains and servers associated with Sality in the U.S. and Europe. The operation involved collaboration with private cybersecurity firms like CrowdStrike and Shadowserver Foundation. Sality's decentralized nature made it difficult to neutralize, but investigators successfully disrupted its command and control mechanisms. This operation highlights the importance of international cooperation in combating long-standing cyber threats.

Key Points: • Sality botnet, active since 2003, was dismantled in a multinational operation. • Over 11 million unique IP addresses were linked to Sality's malware infrastructure. • The operation involved collaboration between law enforcement and private cybersecurity firms.

Timeline

2026-08-31
International operation against Sality botnet
FBI led a multinational effort to dismantle the Sality botnet, involving Romania, Bulgaria, and Hungary.
Digi24
2026-09-03
News coverage of Sality dismantling
Multiple news outlets reported on the successful takedown of the Sality botnet and the role of Romanian authorities.
Newsweek
2026-09-03
FBI praises Romania's contribution
The FBI acknowledged the significant role of Romanian law enforcement in the operation against Sality.
Euronews