A botnet that has been running since 2003 was taken apart in four countries at once, and the method was to turn its own resilience against it

Technology and AI

A botnet that has been running since 2003 was taken apart in four countries at once, and the method was to turn its own resilience against it

By Staff Writer  |  2 September 2026

The upper storeys of the Edward R. Roybal Federal Building and United States Courthouse in Los Angeles rising above trees against a clear sky

Prosecutors in the United States, Bulgaria, Hungary and Romania seized the domains behind Sality on 1 September, while a security company fed the network false information until the infected machines cut themselves off from their operator. The malware has been installing itself on other people's computers for twenty three years, and most of the owners never knew.

Sality is older than most of the companies now writing about it. It was first seen in 2003, and since then it has been quietly installing itself on other people's machines and using them to steal cryptocurrency and to mount attacks on victims in the United States and elsewhere. On 1 September the United States Attorney's Office for the Central District of California announced that it had been taken apart, in an operation running across four countries with two private organisations alongside the police.

The official account is precise about who did what. The Department of Justice, the FBI and the military inspector general's criminal investigative arm, DCIS, seized Sality-linked domains in the United States. Law enforcement in Bulgaria, Hungary and Romania acted against further Sality domains hosted in Europe. Eurojust and Europol assisted, along with the organised crime directorates of all three European forces.

Cybercriminals, botnets, and malware are a clear and present danger to our nation's security and economy. This successful effort to take down the Sality botnet shows that by working together the public and private sectors can be a powerful force for good.

Bill Essayli, First Assistant United States Attorney

Why it survived twenty three years

Most botnets die when somebody seizes the server that controls them. Sality had no such server. It was built peer to peer, so the infected machines passed instructions to one another and the network had no single point an investigator could take. That is why it outlasted three generations of more aggressive criminal enterprises, and why the people who dismantled it did not try to seize a controller at all.

Instead, on 31 August, a security company's threat team ran what the official release calls a peer-to-peer sinkhole operation. In plain terms, they seeded the network with false information until its own components stopped listening to their operator and started listening to somebody else. The design that made Sality durable was the same design that let it be turned.

This was the most complex botnet takeover we have ever done. This was built to be resilient. It was built to survive takedown or takeover. I think that's the reason it's been around for so long.

Tillmann Werner, researcher at CrowdStrike

The FBI's account puts the emphasis on the arrangement rather than the technique.

This unique collaboration among international law enforcement and private sector partners only enhances the FBI's cyber security capabilities and our efforts to neutralize the threat posed by the Sality botnet.

Patrick Grandy, Assistant Director in Charge of the FBI's Los Angeles Field Office

The part that is not finished

Seizing the domains does not clean the machines. The official release records that The Shadowserver Foundation is working with internet service providers and national incident response teams to find the infections and get owners told, which is the slow and unglamorous half of every operation of this kind. The owners of the infected computers, the release notes, were typically unaware that their devices had been taken over at all.

The Department of Justice said Sality was based out of Russia and gave no further detail. Nobody has been publicly identified as its operator, and no arrest was announced. The Russian Embassy in Washington did not immediately respond to a request for comment.

What a business should take from it

Two things. The first is that an infection can sit on an estate for years without producing any symptom its owner would recognise, because the machine is being used for somebody else's purpose and not against its owner. Firms that assume they would have noticed should ask what, specifically, they would have noticed.

The second is about notification. If a device on a company network is identified in this exercise, the notice will arrive through an internet service provider or a national response team rather than from a vendor, and it will name the connection rather than the machine. Any organisation that cannot map its public addresses to its own equipment will lose days at exactly the point where days matter. That is a records question, not a security one, and it is answerable now.

Sality took twenty three years to stop and one night to fall over. The next one will be built by somebody who has read this week's account of how it was done.