$ techbeacon▋
Darkweb

International Law‑Enforcement Strike Dismantles Sality Botnet, Halting Fresh Malware Drops

International Law‑Enforcement Strike Dismantles Sality Botnet, Halting Fresh Malware Drops

U.S. federal prosecutors announced Tuesday that a multinational operation successfully neutralized the Salium peer‑to‑peer (P2P) botnet, a long‑standing platform for distributing malicious software. The takedown, carried out on August 31, 2026, involved coordinated action by agencies from the United States, Bulgaria, Hungary and additional partners, effectively cutting off the network's ability to deliver new malware payloads.

Sality, first identified more than a decade ago, has been prized by cybercriminals for its resilient architecture. Unlike centralized command‑and‑control servers, its P2P design allowed infected machines to share updates and instructions directly, making it difficult for traditional disruption tactics to succeed. Over the years the botnet has been linked to ransomware, information stealers and cryptominers, contributing to a persistent threat landscape.

The operation turned the botnet's own infrastructure against itself. Law‑enforcement teams infiltrated the network, seized control of a substantial portion of the peer nodes, and redirected traffic to a sink‑hole server under their command. By doing so, they were able to prevent the propagation of fresh malicious code while simultaneously gathering forensic data on the botnet’s operators and its global footprint.

Officials highlighted that the success stemmed from years of collaborative intelligence‑sharing and the use of advanced legal tools such as mutual legal assistance treaties. The joint effort also underscored the growing willingness of European nations to cooperate with U.S. agencies on cybercrime cases that cross borders. While the precise number of compromised devices was not disclosed, analysts estimate that the network once controlled hundreds of thousands of endpoints worldwide.

The disruption of Salium marks a rare victory against a P2P botnet that has repeatedly evaded takedown attempts. Cybersecurity experts say the move will likely force adversaries to migrate to alternative platforms or redesign their distribution methods, at least temporarily reducing the volume of automated malware campaigns. Authorities have indicated that investigations will continue to identify the individuals behind the operation, and that the seized data may be used to pursue further prosecutions. The case serves as a reminder that coordinated international action can still outpace even the most adaptive cyber threats.

Rakesh Meena — Rakesh tracks CVEs, zero-days, and exploit disclosures as they break, translating advisories into plain-language impact analysis. Background in vulnerability research, follows NVD and vendor bulletins closely.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related