Peer-to-peer botnet linked to more than 11 million infected IP addresses worldwide taken down
An international operation supported by Europol has disrupted the Sality peer-to-peer (P2P) botnet, a long-running criminal infrastructure used to distribute malicious payloads to thousands of infected computers worldwide.
The coordinated action, carried out on 31 August 2026 and led by the US authorities, targeted a botnet believed to have been operating for more than two decades. At its peak, the botnet gave its operator access to up to one million infected machines worldwide. To date, more than 11 million unique IP addresses have been linked to the infrastructure, which could be used to distribute malicious payloads to compromised devices.
The disruption activity brought together authorities from Bulgaria, Hungary, Romania, and the United States, with the support of Europol and private-sector partners CrowdStrike and the Shadowserver Foundation.
As part of the disruption, a peer-to-peer sinkholing operation was carried out to redirect communications from infected machines away from the criminal infrastructure. This isolated compromised devices from the botnet and rendered the operator’s command channel inoperable.
Disrupting one of the most resilient criminal infrastructures
Unlike botnets that rely on a traditional central command-and-control server, peer-to-peer botnets such as Sality use infected machines to communicate directly with one another. This decentralised structure makes them particularly resilient and difficult to dismantle, as disrupting individual parts of the infrastructure does not necessarily bring down the wider network.
Tackling Sality therefore required sustained international cooperation over several years. Since 2017, Europol has supported law enforcement authorities around the world in working together to identify and take down infrastructure linked to the botnet as different parts of the network were identified across jurisdictions.
In the weeks leading up to the latest disruption, this cooperation intensified, with partners holding weekly operational calls to coordinate their actions. Europol supported the involvement of law enforcement authorities in Bulgaria, Hungary and Romania, helping to coordinate measures against the botnet infrastructure across the different jurisdictions.
Public-private cooperation at the heart of the disruption
The disruption was made possible through close cooperation between law enforcement authorities and private-sector partners, bringing together cyber intelligence, investigative capabilities and technical expertise.
Through Europol’s Cyber Intelligence Extension Programme (CIEP), CrowdStrike and the Shadowserver Foundation worked alongside law enforcement authorities, providing technical expertise and infrastructure analysis in support of the disruption.
Europol’s European Cybercrime Centre (EC3) supported the exchange and analysis of cyber intelligence, and, together with the Joint Cybercrime Action Taskforce, organised operational meetings between all the partners involved. These efforts helped establish a common operational picture of the botnet and its infrastructure, facilitate intelligence sharing among the countries involved, and ultimately develop a coordinated disruption strategy.
The following authorities took part in the disruption activity:
- Bulgaria: General Director Combating Organised Crime
- Hungary: National Bureau of Investigation Cybercrime Department
- Romania: National Police – Directorate for Combating Organised Crime
- United States: US Department of Justice; Federal Bureau of Investigation; Defense Criminal Investigative Service
- Europol
- Eurojust
Empact
The European Multidisciplinary Platform Against Criminal Threats (EMPACT) tackles the most important threats posed by organised and serious international crime affecting the EU. EMPACT strengthens intelligence, strategic and operational cooperation between national authorities, EU institutions and bodies, and international partners. EMPACT runs in four-year cycles focusing on common EU crime priorities.
Facts Only
Sality is a peer-to-peer botnet.
Over 11 million unique IP addresses have been linked to the infrastructure.
The botnet had peak access to one million infected machines.
A disruption operation occurred on 31 August 2026.
The operation was led by United States authorities.
Participating government entities include the US Department of Justice, FBI, Defense Criminal Investigative Service, Bulgaria's General Director Combating Organised Crime, Hungary's National Bureau of Investigation Cybercrime Department, and Romania's National Police – Directorate for Combating Organised Crime.
Supporting organizations include Europol, Eurojust, CrowdStrike, and the Shadowserver Foundation.
A peer-to-peer sinkholing operation was used to redirect communications from infected machines.
Europol has provided support for botnet infrastructure identification since 2017.
The botnet is believed to have operated for more than two decades.
Executive Summary
A coordinated international operation led by United States authorities has disrupted the Sality botnet, a resilient peer-to-peer (P2P) criminal infrastructure that has operated for over twenty years. Unlike traditional botnets with central command servers, Sality utilized a decentralized structure where infected machines communicated directly with one another, necessitating a multi-year collaborative effort to dismantle. At its peak, the operator controlled one million machines, with over 11 million unique IP addresses linked to the network over time.
The disruption, finalized on 31 August 2026, utilized a P2P sinkholing technique to isolate compromised devices and disable the operator's command channel. This success relied on a public-private partnership involving law enforcement from the US, Bulgaria, Hungary, and Romania, alongside technical intelligence from Europol, CrowdStrike, and the Shadowserver Foundation. While the infrastructure has been rendered inoperable, the long-term history of the botnet underscores the inherent difficulty in eradicating decentralized malicious networks.
Full Take
The strongest version of this narrative is a success story regarding the efficacy of the "public-private partnership" model. It demonstrates that while decentralized P2P architectures are designed to resist single-point failures, they can be overcome through sustained, cross-jurisdictional intelligence sharing and the integration of private-sector telemetry.
The narrative relies on a specific paradigm: the "Global Police" framework. It assumes that the centralization of cyber-intelligence under bodies like Europol and the involvement of private security firms are the primary, and perhaps only, viable pathways to security. There is a subtle tension here; the very resilience that makes P2P botnets dangerous—decentralization—is the same quality that makes them difficult for centralized authorities to manage.
The implications for human agency are mixed. While millions of users are freed from an infection, the operation reinforces a dependency on a small circle of state agencies and private vendors (CrowdStrike, Shadowserver) to maintain digital hygiene. The benefit accrues to the state's image of competence and the vendors' perceived necessity.
Patterns detected: none
Root Cause: This narrative is driven by the "institutional victory" paradigm, where the primary goal is to validate the operational utility of the European Multidisciplinary Platform Against Criminal Threats (EMPACT) and similar frameworks.
Bridge Questions:
1. Does the disruption of a P2P botnet lead to a permanent erasure of the threat, or does it simply force the evolution of more stealthy, decentralized protocols?
2. What oversight exists for the "sinkholing" process, and how is the redirected data handled once the criminal channel is closed?
3. If private-sector partners provide the essential "eyes" for law enforcement, who truly owns the intelligence landscape of the modern internet?
Counterstrike Scan: A coordinated influence campaign would use this story to argue that only total cooperation with specific vendors and agencies can protect the public, using the "two-decade" timeline to create a sense of helplessness without institutional intervention. The actual content remains a standard operational announcement and does not match this aggressive pattern.
