The U.S. Department of Justice (DoJ) on Tuesday announced the takedown of a long-standing peer-to-peer (P2P) botnet known as Sality as part of a coordinated law enforcement operation.
The effort was undertaken on August 31, 2026, by authorities from the U.S., Bulgaria, Hungary, and Romania, in collaboration with private industry partners CrowdStrike and the Shadowserver Foundation. To that end, a peer-to-peer sinkhole operation was carried out to eliminate the threat. In tandem, Sality-linked domains have been seized in the U.S. and Europe.
"Cybercriminals, botnets, and malware are a clear and present danger to our nation's security and economy," said First Assistant United States Attorney Bill Essayli. "This successful effort to take down the Sality botnet shows that by working together, the public and private sectors can be a powerful force for good."
Sality has been documented in the wild since 2003, featuring capabilities to infect and modify Windows executable files, and spread additional malicious software designed for credential theft, spam distribution, proxy services, network exploitation, and distributed denial-of-service (DDoS) attacks.
The malware is the work of a threat actor that's tracked by the broader cybersecurity community under the monikers Salty Spider, Kukacka, Sality, KuKu, SalLoad, Kookoo, and SaliCode. The group is believed to be operating out of the Republic of Bashkortostan in Russia.










