US Department of Justice, September 1, 2026
The Department of Justice today announced a multinational operation involving actions in the United States, Bulgaria, Hungary, and Romania, in collaboration with private industry partners CrowdStrike and the Shadowserver Foundation, to disrupt the botnet and malware known as Sality and take down its infrastructure. The victim computers infected with Sality were part of a peer-to-peer (P2P) botnet, which is a network of computers (each a “bot”) infected with the Sality malware and controlled by the Sality operator.
On Monday, CrowdStrike’s Counter Adversary Operations team, in collaboration with the Department of Justice, FBI, DCIS, international law enforcement, and private industry partners executed a peer-to-peer sinkhole operation and coordinated disruption of the Sality botnet. In conjunction with these efforts, private industry partner The Shadowserver Foundation is working with internet service providers and Computer Security Incident Response Teams (CSIRTs) to identify infections and aid in victim notification and remediation.
Investigators and prosecutors from multiple jurisdictions provided crucial assistance, including Bulgaria’s General Directorate Combating Organized Crime, Hungary’s National Bureau of Investigation Cybercrime Department, Romania’s Romanian Police / Directorate for Combating Organized Crime / Central Cybercrime Unit, Eurojust, and Europol. The Department of Justice’s Office of International Affairs provided significant assistance. Assistant United States Attorney Lauren Restrepo of the National Security Division, along with the FBI’s Los Angeles Field Office and DCIS led the U.S. efforts.