Summary
- Law-enforcement agencies in Bulgaria, Hungary, Romania, and the US participated in the Sality disruption.
- US authorities seized Sality-linked domains while European partners acted against additional infrastructure hosted in Europe.
- The operation also uses sinkholing and victim-notification work to reduce a decentralised peer-to-peer botnet that has operated for more than two decades.
Authorities in three European Union member states and the United States have disrupted infrastructure used by Sality, a long-running peer-to-peer malware network associated with cryptocurrency theft and other cyberattacks.
The US Department of Justice said agencies in Bulgaria, Hungary, and Romania participated in the operation alongside the FBI, US defence investigators, CrowdStrike, and the Shadowserver Foundation.
US authorities seized Sality-linked domains, while European law-enforcement partners took action against additional domains hosted in Europe. CrowdStrike and government agencies also carried out a peer-to-peer sinkhole operation designed to divert infected systems away from infrastructure controlled by the botnet’s operators.
Sality has existed in various forms since 2003. Unlike a botnet that depends on a single central command server, its peer-to-peer architecture allows compromised devices to exchange commands and information with one another. That design can make disruption more difficult because removing individual servers does not necessarily disable the wider network.
The Shadowserver Foundation is now working with internet service providers and Computer Security Incident Response Teams to identify infections and assist with victim notification and remediation. That stage is important because infrastructure seizures can degrade a botnet without removing the malware already present on infected devices.
The multinational structure of the operation reflects where modern cybercrime infrastructure actually sits. Domain registration, hosting, compromised systems, operators, victims, and financial activity frequently cross several jurisdictions, making purely national takedowns less effective against networks capable of relocating or rebuilding services quickly.
European participation involved Bulgaria’s General Directorate Combating Organized Crime, Hungary’s National Bureau of Investigation Cybercrime Department, and the Romanian Police’s Central Cybercrime Unit. Eurojust and Europol also assisted the operation.
For law enforcement, peer-to-peer botnets create a different resilience problem from conventional centralised criminal services. Their topology reduces dependence on infrastructure that can be seized through one court order, while infected endpoints may continue communicating even after some domains and services have been removed.
Sinkholing addresses part of that problem by redirecting malicious communications towards infrastructure controlled by defenders. It can reduce the operator’s ability to command infected devices and provide visibility into remaining infections, but the effectiveness of the approach depends on the protocol, the botnet’s update mechanisms, and whether operators can distribute replacements.
The Sality operation also illustrates the growing role of private organisations in large-scale disruption activity. Security companies can bring telemetry and technical reverse engineering, while organisations such as Shadowserver provide infrastructure and notification capacity that government agencies may not operate at equivalent scale.
That model has become increasingly important as cybercrime operations distribute infrastructure across hosting providers and jurisdictions. Legal authority is necessary to seize or redirect domains, but technical work is required to identify the network, understand how its nodes communicate, and prevent disruption activity from creating unintended effects.
The Justice Department has not said that Sality has been permanently dismantled, and the operation should be treated as a disruption rather than evidence that every infected system or operator has been removed. Its immediate effect is to reduce infrastructure available to the malware and improve visibility into devices still participating in the network.
The durability of the operation will depend on whether remaining Sality nodes can be cleaned up faster than operators can reconstitute control paths — an issue that applies well beyond this botnet to the wider economics of international cybercrime disruption.





