By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Authorities Disrupt Sality Botnet Using Its Own P2P Network

Law enforcement agencies, in a coordinated international operation, have successfully disrupted the Sality peer-to-peer (P2P) botnet, a significant threat that has been active for over a decade. The U.S. Department of Justice (DoJ) announced the takedown on Tuesday, August 31, 2026, detailing how authorities leveraged the botnet's own P2P network to prevent the delivery of new malware payloads. This strategic maneuver effectively cut off the botnet's ability to infect new machines and distribute its malicious software.
The operation involved a multi-national effort, with law enforcement from the United States, Bulgaria, Hungary, and Romania collaborating closely. This international cooperation was crucial in dismantling a botnet that operated across borders and infected hundreds of thousands of computers globally. The success of the operation was further bolstered by the technical expertise and support provided by private industry partners, specifically CrowdStrike, a cybersecurity firm known for its threat intelligence, and the Shadowserver Foundation, a non-profit organization dedicated to combating cybercrime by collecting and disseminating threat data.
The Sality botnet was notorious for its sophisticated P2P architecture, which made it resilient to traditional takedown methods. Unlike botnets that rely on centralized command-and-control (C2) servers, Sality's nodes communicated directly with each other, allowing infected computers to act as both clients and servers. This decentralized nature meant that taking down a few servers would not cripple the entire network. The attackers behind Sality used it to distribute various forms of malware, including information stealers, backdoors, and ransomware, and it was also known for its ability to evade detection by antivirus software.
By turning Sality's own P2P network against it, authorities were able to inject commands that effectively blocked new connections and prevented the botnet's controllers from issuing further instructions or distributing updated malware. This method is a significant advancement in cyber warfare, demonstrating an ability to subvert the very infrastructure used by cybercriminals. The DoJ stated that this action significantly degrades the botnet's capabilities and aims to protect internet users from its ongoing malicious activities. The investigation into the individuals responsible for operating the Sality botnet is ongoing, with authorities seeking to identify and prosecute those involved in its creation and maintenance.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.