Press TechRound interviews Secure.com CEO on the future of AI security
Read

Two Decades On, Investigators Turn Sality’s Own Network Against It

A 23 year old peer to peer botnet named Sality was dismantled after hitting 15,000+ machines. Here is what happened and how to check for it.

Dateline: September 2, 2026

TL;DR: One of the internet’s oldest surviving botnets is finally offline. On August 31, investigators dismantled Sality, a peer to peer botnet that had been running since 2003. That is 23 years of quietly infecting machines, stealing money, and dodging every attempt to shut it down. The method used to kill it was almost poetic. The same design choice that made Sality so hard to catch is what let investigators unravel it.

What Happened?

Sality never relied on a single command server. Most botnets do, and that central point is usually how they get taken down. Sality instead spread across infected machines that talked to each other directly. Knock out one node and the rest kept going. That decentralised design is why it took years of coordinated work across four countries and two private research teams to bring it down.

The breakthrough came from a weakness hiding in plain sight. Sality bots trusted any machine that answered a simple handshake. There was no authentication and no way to tell a real infected host from an impostor. So investigators built their own fake peers, called sinkholes, and slipped them into the network. Every 40 minutes the botnet checks whether its known peers are still alive. That routine maintenance cycle was hijacked. Real peers got purged, sinkhole entries took their place, and infected machines were slowly cut off from the operator. Payload hosting URLs and related domains were seized at the same time.

What’s the Impact?

At its core, Sality was a money machine. Its main payload watched a victim’s clipboard for cryptocurrency wallet addresses and quietly swapped in attacker controlled ones. Estimates put the haul from that trick at around $150,000. But the botnet was flexible. Over the years it ran spam, proxy services, and at least three separate denial of service campaigns, one launched a day after the invasion of Ukraine began. It even showed up in an industrial setting, roping programmable logic controllers into its ranks.

Here is the part that matters for defenders. The takedown stops Sality from pushing new payloads, but it does not clean infected machines. Malware already sitting on a device stays active until someone removes it. If a machine was compromised last week, it is still compromised today. The operation bought time and cut off the supply line. The cleanup is still on you.

A quieter takedown than the headline suggests

There is no arrest to celebrate here, no operator in handcuffs. The infrastructure is neutralised, not the person behind it. For security teams, that is the honest read. The threat is degraded, not gone, and thousands of machines around the world are still infected and waiting.

How to Avoid This

Old malware sticks around because it keeps finding unpatched, unmonitored corners of a network. A few steps close those gaps:

  • Hunt your logs for traffic to the sinkhole address listed in the IOC sheet. A hit means an active infection.
  • Block the known payload URLs across your proxy and DNS logs.
  • Restrict USB and network share access, since that is how Sality spread for years.
  • Keep Windows executables and endpoints monitored for file infector behavior, not just known signatures.
  • Do not assume a takedown equals a cleanup. Scan and remediate any machine that beacons out.