File Photo | Photo Credit: Europol Multimedia

An international operation supported by Europol has disrupted the Sality peer-to-peer botnet, a criminal network linked to more than 11 million infected IP addresses worldwide. The coordinated action, led by U.S. authorities on Aug. 31, 2026, targeted infrastructure believed to have been active for more than 20 years.

At its peak, Sality reportedly gave operators access to as many as one million infected computers. The network was used to distribute malicious payloads to compromised devices and relied on a decentralized peer-to-peer structure, making it more difficult to dismantle than botnets controlled through a central server.

Authorities in Bulgaria, Hungary, Romania and the United States took part in the operation, alongside Europol, Eurojust and private-sector partners CrowdStrike and the Shadowserver Foundation. Investigators used a peer-to-peer sinkholing operation to redirect communications from infected machines away from the criminal infrastructure, isolating devices and disabling the operator’s command channel.

Europol said cooperation against Sality had been ongoing since 2017, with intelligence-sharing and coordination intensifying in the weeks before the latest disruption. The agency’s European Cybercrime Centre and Joint Cybercrime Action Taskforce helped organize operational meetings and develop a joint strategy with law enforcement and cybersecurity partners.