Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
5SEP

Europol sinkholes Sality after two decades

2 min read
12:09UTC

Europol announced on 2 September that an operation led by US authorities had sinkholed Sality, a peer-to-peer botnet active for two decades. CrowdStrike and the Shadowserver Foundation did the technical work.

TechnologyAssessed
Key takeaway

Sality's infections survive the takedown; only the operator's ability to command them has been removed.

Europol, the European Union's police agency, announced on 2 September that an international operation had disrupted Sality, a peer-to-peer botnet active for two decades 1. US authorities led the action on 31 August, Bulgaria, Hungary and Romania took part, and two private organisations ran the technical side alongside the police: CrowdStrike, an American security vendor, and the Shadowserver Foundation, a non-profit that scans the internet for compromised machines and reports them to national CERTs.

A botnet turns a population of infected computers into a resource that takes orders from somebody else. Most botnets run on central command servers, which is what makes them seizable. Sality does not: infected machines pass instructions to each other, so there is no address to raid. Investigators used peer-to-peer sinkholing, feeding the network's own gossip protocol until infected machines took their instructions from the investigators rather than from the operator, and the command channel stopped answering. The infection stays exactly where it was; what has been removed is the ability to give it orders.

Europol says more than 11 million unique internet protocol addresses were linked to the infrastructure, which counts addresses touched over time rather than victims, since a home connection can carry a new address every week. At its peak the operator could reach roughly one million infected machines. Every one of those machines still runs Sality's code, which makes the residual population standing inventory for whoever writes the next command layer.

Europol's Operation Saffron in May took the opposite route, seizing 33 servers from an anonymisation service that at least 25 ransomware gangs relied on . Saffron took property, which requires a warrant, a jurisdiction and a rack. This action took a protocol, which required neither, and the composition of the team says why: a commercial vendor and a non-profit held the capability that the police action needed.

Deep Analysis

In plain English

A botnet is a network of infected computers an attacker controls remotely, often without the owner knowing. Sality is one of the oldest, running for about 20 years. Law enforcement from several countries, led by the US, worked with security firms to disrupt it on 31 August. 'Sinkholing' means redirecting the botnet's traffic to servers law enforcement controls instead of the criminal operators', cutting the attackers off from the infected machines.

First Reported In

Update #13 · Four privileged platforms under live attack

Europol· 5 Sept 2026
Read original
Causes and effects
This Event
Europol sinkholes Sality after two decades
Sality keeps no central server to seize, so the operation had to take the network's own gossip protocol away from its operator.
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.