Global Law Enforcement Dismantles Long-Running Sality Botnet
Law enforcement agencies from multiple countries, working alongside private cybersecurity firms, have taken down infrastructure powering the Sality botnet, one of the internet's longest-running malware networks. Sality has been active for well over a decade, using a peer-to-peer architecture that let infected machines communicate directly with one another rather than relying on a single command server, making it notoriously resilient to takedown attempts.
The operation targeted the servers and domains used to control and update infected devices, aiming to sever communication channels that let the botnet's operators issue commands, distribute additional malware, or harvest data from compromised systems. Because of its P2P design, Sality has historically survived earlier disruption efforts by other researchers and agencies.
Details on exactly how many infected systems remain active, or which countries led the effort, are still emerging, but the action represents a significant, coordinated blow to one of the internet's oldest botnet ecosystems.