Skip to content
archivemalware · 02 Sep 2026 · 08:56 UTC

Global sinkhole operation ends Sality botnet’s 23-year run

last 60 dispatches · spectrum

Sality, a peer-to-peer (P2P) botnet that had been running for 23 years and infecting more than 15,000 machines worldwide, has been taken down in a joint operation by international law enforcement agencies, working with CrowdStrike and the Shadowserver Foundation. The operation cut Sality’s operator off from every infected machine still under their control. …

grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected