# Sality Is Dead — Or Is It? Inside the Takedown of a Botnet That Refused to Die
Twenty-three years is an eternity in malware years. The Sality botnet — first spotted in the wild in 2003, when most of today's security engineers were still in middle school — just got the takedown treatment from a coordinated international law enforcement effort backed by private sector partners. Infrastructure seized, nodes disrupted, headlines declaring victory.
But anyone who's followed P2P botnet takedowns knows the story rarely ends at the press release.
## Why Sality Lasted Two Decades
Most botnets die young. A C2 server gets seized, the communication channel collapses, and the infected machines go quiet waiting for commands that never come. Operators regroup, maybe rebrand, and the cycle starts over.
Sality was built differently — and deliberately so. Its peer-to-peer architecture meant there was no central command-and-control to knock offline. Infected machines communicated directly with each other, sharing tasks, distributing updates, electing peers to relay instructions. To kill it, you couldn't just pull a server. You had to poison the peer list, sinkhole the traffic, and convince enough nodes that their neighbors were gone.
This is exactly the architecture that made Sality so resilient against the periodic "disruptions" announced over the years. Law enforcement seized infrastructure components in earlier actions — and Sality kept running. The botnet weathered takedown attempts that would have flatlined centralized operations, because each infected machine was simultaneously a victim, a relay, and a potential command node.
The current action appears to be more aggressive than previous efforts: coordinated seizures of infrastructure components combined with private sector involvement in sinkholing operations. Whether "dismantled" means permanently dead or temporarily hobbled is the question every network defender should be asking right now.
## What Sality Actually Does
Before treating this as a historical footnote, it's worth being specific about what Sality's infected population was capable of — because the botnet's age doesn't make it quaint.
Sality-infected machines have historically been used for:
That last point matters. Sality infections in the wild frequently served as the initial foothold for more targeted follow-on compromise. A machine sitting on a corporate network with a years-old Sality infection might have been used for far more than spam.
The botnet spread primarily through infected executables and removable media — the kind of lateral movement that was devastatingly effective in the era before endpoint detection matured, and remains a vector on the industrial and OT networks that never got upgraded.
## The Peer-to-Peer Problem Never Really Gets Solved
The difficulty of P2P botnet takedowns has a documented history. Rustock, Gameover Zeus, Kelihos — each required extensive private-public coordination, sinkholing operations running for months, and cooperation from ISPs across multiple jurisdictions. Gameover Zeus, arguably the most sophisticated P2P botnet before Sality's era of peak activity, required a coordinated two-week window before operators could rebuild infrastructure.
Sality's operators — assuming the botnet still has active human stewardship rather than running on residual momentum — have had this playbook available for years.
The honest read on any P2P botnet takedown announcement is this: the infrastructure is disrupted, not destroyed. Sinkholing redirects traffic to researcher-controlled nodes. Infected machines still exist. The malware on those endpoints doesn't uninstall itself because law enforcement filed a seizure order.
## What Defenders Actually Need to Do Right Now
This takedown is not a reason to stand down. It's a reason to audit.
If you're running endpoint detection, pull your telemetry for Sality indicators — the YARA rules are publicly available and have been for years. Sality's file infection behavior leaves distinct signatures that modern EDR should catch, but "should catch" and "is catching" are different statements.
Specific environments that warrant immediate attention:
Sality's spread vector — USB and shared drives — is particularly dangerous in environments where removable media policies are treated as suggestions. An infection that's been dormant on an air-gapped-in-theory machine can reactivate the moment someone plugs in a drive.
---
## HackWire Analysis
The Sality takedown is genuinely significant — but the framing matters enormously.
What makes this story worth examining carefully is the age of the target. A botnet that's been operational for over two decades isn't just a malware sample; it's a mirror. Sality's survival through multiple takedown attempts, two decades of endpoint security evolution, and the collapse of its primary spread vectors reflects something uncomfortable: we are still finding and disrupting infections from 2003 on networks that ostensibly have modern defenses.
The pattern here matches what we saw after Emotet's January 2021 takedown. Law enforcement announced the network disrupted, private researchers celebrated, and then — months later — Emotet rebuilt. The rebuilt version was meaner, with improved evasion. Operators who ran botnets sophisticated enough to survive for two decades don't simply retire because one infrastructure batch got seized.
There's also a dimension other coverage has largely skipped: the proxy relay use case. Sality's infected machines have long been harvested as anonymizing infrastructure for other criminal operations. The disruption of that proxy pool could temporarily impact separate criminal campaigns that were renting Sality's infected nodes as middle-boxes — a second-order effect worth monitoring.
For defenders, the real takeaway isn't "Sality is gone." It's "you now have a window." When P2P botnet takedowns happen, the remaining infected nodes often go quiet or erratic as they search for peers that no longer answer. This is exactly the moment to run your endpoint scans, pull your DNS logs for historical Sality C2 patterns, and check whether anything in your environment was silently part of this network.
The window won't last. Act accordingly.
— HackWire Editorial
---
## Related Coverage