# Law Enforcement Just Weaponized Sality's Own Botnet Against Itself


For more than two decades, Sality survived everything thrown at it. Antivirus vendors catalogued it. Researchers mapped its infrastructure. Takedown attempts came and went. The botnet kept spreading, kept infecting, kept serving payloads to a sprawling network of compromised machines — because it was built, from the ground up, to outlast exactly those kinds of attacks.


On August 31, 2026, that finally changed. But not by destroying Sality from the outside. By turning it against itself.


## The Architecture That Made Sality Almost Untouchable


Most botnets have a fatal structural weakness: a centralized command-and-control server. Find the server, seize it, and the botnet goes deaf. Researchers and law enforcement have been exploiting that chokepoint for years.


Sality's authors understood this. The botnet's P2P architecture, refined over successive versions going back to roughly 2003, distributes command-and-control across thousands of infected nodes simultaneously. There's no single throat to cut. Every infected machine is simultaneously a client and a relay — receiving commands and propagating them to peers. Take down a hundred nodes and the remaining thousands carry on, completely unaffected.


This is why Sality kept running while newer, flashier botnets rose and fell around it. Kelihos fell in 2017. Emotet got dismantled in 2021. Qakbot went down in 2023. Sality just kept going.


## What "Turning the Network Against Itself" Actually Means


The DoJ's announcement — executed in coordination with Bulgarian, Hungarian, and Romanian authorities alongside CrowdStrike and the Shadowserver Foundation — describes cutting off new malware payloads by weaponizing Sality's own P2P infrastructure.


The mechanics here matter. In P2P botnet disruption, there are a few established techniques. The most aggressive is peer poisoning: law enforcement compromises or legally seizes enough nodes within the botnet's peer list to inject their own "peers" — nodes they control — at sufficient scale to achieve a kind of democratic majority. Once you control enough legitimate-looking peers in the network, you can substitute null payloads, push update commands, or simply refuse to propagate legitimate operator commands downstream.


Shadowserver's involvement strongly suggests peer-list monitoring and sinkholing was part of the operation. They've run botnet sinkholes for years, and their infrastructure gives law enforcement visibility into which IPs are actively participating in the network at any given moment. CrowdStrike's role likely contributed threat intelligence and potentially endpoint telemetry to identify high-value Sality nodes worth targeting for seizure.


The four-country coordination wasn't incidental. Sality's P2P mesh spans Europe heavily — Bulgaria, Hungary, and Romania have long appeared in Sality peer-list data. Seizing nodes in those jurisdictions wasn't a diplomatic formality; it was tactically essential.


## Twenty-Three Years Is a Long Time


It's worth sitting with that number. Sality has been a continuous, functional threat since approximately 2003. Most of the security professionals now working detection and response were in middle school when this thing first appeared. It infected Windows XP machines. It predates the iPhone.


Its longevity reflects both the sophistication of its architecture and something grimmer: the sheer number of machines that remain unpatched, poorly monitored, or simply forgotten. Sality spreads through executable file infection and removable media — USB drives, network shares, the same infection vectors that were dominant two decades ago. The fact that it could still operate at meaningful scale in 2026 says something unflattering about the state of baseline hygiene across a significant chunk of the connected world.


## What Isn't Fixed


Here's the detail that deserves more attention than it will get: this disruption cuts off new payloads, but it does not clean infected machines.


Sality is a file infector. It doesn't just install a malicious process — it modifies existing executable files on compromised systems, prepending or appending its code to legitimate binaries. Killing the botnet's payload distribution infrastructure means operators can no longer push new modules, ransomware, or credential stealers through the network. That's genuinely significant. But the underlying infections don't disappear.


Every machine that was running Sality on August 30th is still running Sality code on September 1st. Those infected executables are still sitting on disk. If the P2P disruption degrades or operators route around it — which botnet operators have done before, most notably when the Emotet core group partially reconstituted itself after the 2021 takedown — those machines are already primed to reconnect.


The Qakbot operation in 2023 took the more aggressive approach of pushing an uninstaller through the botnet's own channels. The DOJ hasn't announced anything similar here, which may reflect the technical complexity of reversing file-level infections at scale.


---


## HackWire Analysis


The Sality takedown is a milestone, but the more important story is what it reveals about how law enforcement has evolved its playbook for P2P infrastructure.


The old approach — seize the C2 server, get a court order, declare victory — never worked against distributed architectures. What's emerged over the last several years is a fundamentally different methodology: infiltrate the peer network at sufficient depth to achieve operational influence over it, then use the botnet's own trust mechanisms against it. That's what happened with Qakbot. That's what appears to have happened here.


The pattern is accelerating. Each successive operation builds institutional knowledge at agencies like DOJ and at private partners like CrowdStrike and Shadowserver about how to map P2P topologies, identify strategically valuable nodes, and coordinate multi-jurisdiction seizures at the tempo and scale needed to actually disrupt a distributed network before operators can react. The four-country coordination on Sality executed simultaneously — that takes years of relationship-building and operational planning to pull off cleanly.


The meaningful risk that other coverage is underplaying: Sality's infection base is probably concentrated in industrial, manufacturing, and small-business environments — exactly the sectors that still run Windows versions from the 2000s and 2010s on operational equipment that nobody wants to touch because it controls something expensive. Those machines didn't get the takedown notification. They're still infected, still capable of being reactivated if the P2P disruption erodes, and most of the organizations running them have no idea Sality exists on their network. The window between payload disruption and actual remediation is where the real exposure lives.


Defenders should be running Sality-specific IOC searches against endpoint telemetry now, not after a re-emergence event.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Malware](https://www.hackwire.news/category/malware) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)