Europol, the European Union's police agency, announced on 2 September that an international operation had disrupted Sality, a peer-to-peer botnet active for two decades 1. US authorities led the action on 31 August, Bulgaria, Hungary and Romania took part, and two private organisations ran the technical side alongside the police: CrowdStrike, an American security vendor, and the Shadowserver Foundation, a non-profit that scans the internet for compromised machines and reports them to national CERTs.
A botnet turns a population of infected computers into a resource that takes orders from somebody else. Most botnets run on central command servers, which is what makes them seizable. Sality does not: infected machines pass instructions to each other, so there is no address to raid. Investigators used peer-to-peer sinkholing, feeding the network's own gossip protocol until infected machines took their instructions from the investigators rather than from the operator, and the command channel stopped answering. The infection stays exactly where it was; what has been removed is the ability to give it orders.
Europol says more than 11 million unique internet protocol addresses were linked to the infrastructure, which counts addresses touched over time rather than victims, since a home connection can carry a new address every week. At its peak the operator could reach roughly one million infected machines. Every one of those machines still runs Sality's code, which makes the residual population standing inventory for whoever writes the next command layer.
Europol's Operation Saffron in May took the opposite route, seizing 33 servers from an anonymisation service that at least 25 ransomware gangs relied on . Saffron took property, which requires a warrant, a jurisdiction and a rack. This action took a protocol, which required neither, and the composition of the team says why: a commercial vendor and a non-profit held the capability that the police action needed.
