A multinational operation has disrupted Sality, one of the internet's longest-running malware networks, after more than two decades of activity.
US officials, European partners and cybersecurity company CrowdStrike targeted the botnet's peer-to-peer infrastructure and associated domains. Sality first appeared in 2003 and survived repeated defensive efforts because infected computers could communicate with one another without relying on a single central server.
What Sality did
Sality infected Windows computers and turned them into remotely controlled nodes. Operators could use those machines for spam, distributed denial-of-service attacks, cryptocurrency theft and delivery of additional malware.
An infected user might notice slow performance or security warnings, but many machines continued operating normally enough to remain part of the network for years.
The botnet's longevity created another advantage for criminals: old infections remained active in poorly maintained computers, while new versions adapted to changing security tools.
Why peer-to-peer botnets are difficult to stop
Traditional botnets often depend on command-and-control servers. Investigators can seize those servers or redirect their domains, cutting the operator off from infected devices.
Sality used peer-to-peer architecture. Individual infected computers exchanged information with other nodes, allowing the network to continue even when parts were removed.
That design forced investigators to understand the communication protocol and influence the information travelling inside the botnet rather than simply unplugging one machine.
How the disruption worked
CrowdStrike injected false routing information into Sality's peer-to-peer network, separating infected computers from the criminal controller. The technique effectively poisoned the botnet's internal map so that commands could no longer travel through the expected paths.
The FBI and US Department of Justice coordinated seizures of domains used by the operation, while European agencies and the Shadowserver Foundation supported the wider disruption.
CrowdStrike researcher Tillmann Werner called it the company's most complex takedown because of Sality's resilience and decentralized structure.
Is Sality completely gone?
A disruption is not always permanent eradication. The person behind Sality has not been publicly identified, and investigators are watching for attempts to rebuild control or update infected machines with new instructions.
Some computers may still contain the malware even if they are no longer receiving commands. Owners should not assume that the takedown cleans individual devices.
Security teams can use updated detection tools, scan endpoints and reinstall compromised systems where necessary. Unsupported versions of Windows are especially risky because they no longer receive normal security patches.
Why the operation matters globally
Botnets ignore national boundaries. A controller in one country can exploit household and business computers across dozens of jurisdictions, creating legal and technical obstacles for investigators.
Coordinated takedowns demonstrate that law enforcement and private researchers can act against infrastructure even when the primary operator remains unknown. They also provide intelligence about criminal methods that can help disrupt future networks faster.
The Sality operation is a reminder that cyber threats do not have to be new to remain dangerous. Malware built in the early 2000s can survive through architecture, continuous modification and millions of neglected computers.
What users should do
Users should install operating-system and antivirus updates, remove unsupported software and avoid executing files from unknown sources. Organizations should monitor unusual outbound traffic and isolate systems showing signs of compromise.
Anyone responsible for an older network should treat the takedown as an opportunity to scan rather than a reason to relax. Sality's command structure may be disrupted, but any machine infected by it has already demonstrated a security weakness that another attacker can exploit.
After 20 years, the botnet has lost much of its ability to receive coordinated commands. The final measure of success will be whether defenders can keep it disconnected—and prevent its operator from building a replacement.
Source: Reuters cybersecurity report.

