Europol and CrowdStrike shut down Sality botnet

Published September 2, 2026

Europol and CrowdStrike shut down the Sality botnet, a 20-year-old network of infected computers controlled by a single operator. They used a special trick to cut off the operator from all the machines it was controlling.

Report priority
Medium

How it works

  • The operator ran a hidden network of infected computers, letting them send commands to each other without needing a central server.
  • Europol and CrowdStrike tricked the network into connecting to a fake command center instead.

What to do

Check your antivirus logs or scan your computer for signs of infection. If you suspect your device was part of the botnet, run a full antivirus scan and update your security software to prevent future infections.

Technical details

Europol and CrowdStrike disrupted the Sality botnet, a 20-year P2P network, using a peer-to-peer sinkhole to cut its operator off from infected machines.