Overview
- U.S. prosecutors and the FBI announced Sept. 1, 2026 that they had seized Sality‑linked domains in the United States and coordinated domain actions with law enforcement in Bulgaria, Hungary and Romania.
- CrowdStrike demonstrated an active disruption at its Day Zero summit by reverse‑engineering Sality and seeding the peer‑to‑peer network with bogus data that tricked infected nodes into cutting off the operator.
- The takedown relied on private and nonprofit partners, including The Shadowserver Foundation, to map the botnet, identify weak points and locate infected hosts for follow‑up remediation.
- Investigators have not publicly identified Sality’s creator, and officials said they will monitor for attempts to regain control or rebuild the network while urging owners to clean compromised devices.
- Sality has run since 2003 and has been used for spam, distributed denial‑of‑service attacks and cryptocurrency theft, so the work to remove malware from thousands of machines worldwide will determine whether the disruption holds.