Sality Malware Disrupted in International Cyber Takedown
LOS ANGELES / Tuesday, September 1, 2026 – The Department of Justice today announced a multinational operation involving actions in the United States, Bulgaria, Hungary, and Romania, in collaboration with private industry partners CrowdStrike and the Shadowserver Foundation, to disrupt the botnet and malware known as Sality and take down its infrastructure.
Coordination between the private sector and government partners was central to this effort and advanced the first pillar of President Trump’s Cyber Strategy for America – “Shape Adversary Behavior.” Federal law enforcement worked with the private sector to identify and disrupt malicious networks, scale national capabilities, and shape adversary behavior by degrading their tools and infrastructure.
“Cybercriminals, botnets, and malware are a clear and present danger to our nation’s security and economy,” said First Assistant United States Attorney Bill Essayli. “This successful effort to take down the Sality botnet shows that by working together the public and private sectors can be a powerful force for good.”
“This unique collaboration among international law enforcement and private sector partners only enhances the FBI’s cyber security capabilities and our efforts to neutralize the threat posed by the Sality botnet,” said Patrick Grandy, the Assistant Director in Charge of the FBI’s Los Angeles Field Office. “The FBI will continue working with our partners to prevent further cyber-enabled attacks and theft from victims in the United States.”
“Protecting the integrity of the Department of Defense Information Network from clear threats like the Sality botnet is a top priority for us,” said Special Agent in Charge Kenneth DeChellis of the Department of Defense Office of Inspector General’s Defense Criminal Investigative Service (DCIS), Cyber Field Office. “Today’s announcement is the result of the shared commitment and long-standing partnership between international law enforcement and the private sector.”
Since 2003, the Sality botnet has installed malicious software (malware) on compromised devices, enabling cryptocurrency theft and cyberattacks on victims in the United States and abroad.
The victim computers infected with Sality were part of a peer-to-peer (P2P) botnet, which is a network of computers (each a “bot”) infected with the Sality malware and controlled by the Sality operator. A P2P botnet is a decentralized network of bots that communicate directly with each other to share commands. The owners of the victim computers were typically unaware that their devices had been misappropriated as bots by Sality.
On Monday, CrowdStrike’s Counter Adversary Operations team, in collaboration with the Department of Justice, FBI, DCIS, international law enforcement, and private industry partners executed a peer-to-peer sinkhole operation and coordinated disruption of the Sality botnet.
As part of the international operation, the Department of Justice, FBI, and DCIS seized Sality-linked domains in the United States. International law enforcement partners in Bulgaria, Hungary, and Romania took action against additional Sality-linked domains hosted in Europe.
In conjunction with these efforts, private industry partner The Shadowserver Foundation is working with internet service providers and Computer Security Incident Response Teams (CSIRTs) to identify infections and aid in victim notification and remediation.
Investigators and prosecutors from multiple jurisdictions provided crucial assistance, including Bulgaria’s General Directorate Combating Organized Crime, Hungary’s National Bureau of Investigation Cybercrime Department, Romania’s Romanian Police / Directorate for Combating Organized Crime / Central Cybercrime Unit, Eurojust, and Europol. The Department of Justice’s Office of International Affairs provided significant assistance.
Assistant United States Attorney Lauren Restrepo of the National Security Division, along with the FBI’s Los Angeles Field Office and DCIS led the U.S. efforts.
Contact
Ciaran McEvoy
Public Information Officer
ciaran.mcevoy@usdoj.gov
(213) 894-4465
Source: U.S. Attorney's Office, Central District of California












