Cops bring down ancient million-machine Sality botnet after nine-year battle

Criminal operators used decentralized peer-to-peer infrastructure to keep zombie network alive throughout the 21st century.

Share
Sality is linked to more than 11 million IP address - with operators controlling one million machines during the botnet's peak (Image: ChatGPT)
Sality is linked to more than 11 million IP address - with operators controlling one million machines during the botnet's peak (Image: ChatGPT)

The Sality botnet was active for two decades, using a decentralized peer-to-peer structure to dodge law enforcement.

Now cops and private-sector investigators have smashed this ancient zombie network using a technique called sinkholing, which redirects communications from infected devices away from criminal infrastructure and toward defender-controlled systems.

Europol said this isolated compromised devices from the botnet and made the operator’s command channel inoperable.

Sality has been active since 2003 and deploys malware enabling cryptocurrency theft and further cyberattacks.

"At its peak, the botnet gave its operator access to up to one million infected machines worldwide," Europol wrote.

"To date, more than 11 million unique IP addresses have been linked to the infrastructure, which could be used to distribute malicious payloads to compromised devices."

Sality did - or does - not rely on a traditional central command-and-control server, instead allowing infected machines to communicate directly with one another peer-to-peer.

"This decentralized structure makes them particularly resilient and difficult to dismantle, as disrupting individual parts of the infrastructure does not necessarily bring down the wider network," Europol wrote.

As well as Europol and the DoJ, investigators from Bulgaria, Hungary and Romania, as well as CrowdStrike and the Shadowserver Foundation, worked to take down Sality.

Sality: Est. 2003

European cops have been fighting the botnet for almost a decade, first starting their operation in 2017.

The DoJ said the collaboration between the private and public sectors has "advanced the first pillar" of President Trump’s Cyber Strategy for America: "Shape Adversary Behavior."

In this case, the behavior of bad guys was shaped by "degrading their tools and infrastructure."

In many cases, victims were unaware their devices had been "misappropriated as bots," the DoJ continued.

READ MORE: China-linked "Fire Ant" hackers nest inside telecoms routers to swarm critical infrastructure

“Cybercriminals, botnets, and malware are a clear and present danger to our nation’s security and economy,” said First Assistant United States Attorney Bill Essayli. “This successful effort to take down the Sality botnet shows that by working together the public and private sectors can be a powerful force for good.”

American law enforcement specifically identified the Pentagon's global information network as infrastructure it was seeking to protect from the botnet.

“Protecting the integrity of the Department of Defense Information Network from clear threats like the Sality botnet is a top priority for us,” added Special Agent in Charge Kenneth DeChellis of the Department of Defense Office of Inspector General’s Defense Criminal Investigative Service (DCIS), Cyber Field Office.

Battle of the bots

Botnets have existed in recognizable form since at least the late 1990s, when malware authors began remotely controlling networks of compromised computers over internet relay chat (IRC). Early examples included PrettyPark, which appeared in 1999 and could connect infected Windows machines to IRC servers, allowing them to receive commands remotely.

The 2000s brought much larger and more sophisticated networks. Agobot, also known as Gaobot, emerged around 2002 and spawned numerous variants, while Sdbot became the basis for a sprawling family of IRC-controlled malware.

By the middle of the decade, botnets containing hundreds of thousands or even millions of compromised computers had become a major part of the cybercrime economy.

Other botnets also became harder to destroy as their creators moved away from centralized command servers. Storm, which appeared in 2007, used peer-to-peer communications, while Conficker spread explosively from 2008 and infected millions of Windows computers.

Some of these old malware populations proved extraordinarily persistent, with infected machines continuing to appear on the internet years after the botnets' heyday.

READ MORE: "Iranian hackers" shut down a UK power station. The next incident could be much worse

Botnets are far from a relic of the early web. Cloudflare recorded 47.1 million DDoS attacks in 2025, up 121% in a year, as enormous networks of compromised devices helped drive attacks to record-breaking levels.

Modern botnets can recruit everything from compromised routers and security cameras to Android devices and other internet-connected hardware, giving their operators enormous pools of computing power and bandwidth. One of the largest recent examples, Aisuru-Kimwolf, is estimated to control between one million and four million infected hosts.

That scale has translated into unprecedented attack power. In November 2025, Cloudflare detected a record-breaking DDoS attack attributed to Aisuru that peaked at 31.4 terabits per second. Cloudflare recorded 19 attacks that set new records during 2025, illustrating how rapidly the destructive capacity available to botnet operators has increased.

Botnets are not limited to DDoS attacks. Once criminals control a compromised machine, they can potentially use it to distribute additional malware, send spam, steal credentials, conduct fraud or provide infrastructure for other cybercriminal operations.

Follow Machine on LinkedIn