Security / WORLD

Europol-backed operation targets Sality botnet infrastructure

Europol said an international action on 31 August targeted Sality botnet infrastructure linked to more than 11 million unique IP addresses.

Reading sizeSources ↓Share story ↗

Europol announced on 2 September 2026 a coordinated action led by US authorities with Bulgaria, Hungary and Romania. It said the Sality peer-to-peer botnet had been used for years to distribute malicious payloads and that more than 11 million unique IP addresses had been linked to its infrastructure.

At its peak, the botnet was believed to have given its operator access to as many as one million infected machines worldwide, according to Europol. The European Cybercrime Centre supported intelligence sharing and operational meetings; the reported IP-address total does not represent a count of infected devices.

Data

Timeline

Security development

Security event or institutional action reported by the source.

  1. · Occurred

    Coordinated action against the Sality botnet

    The US-led action targeted the botnet infrastructure with Bulgaria, Hungary and Romania. Europol said more than 11 million unique IP addresses had been linked to the infrastructure.

Methodology

The event date and description summarise the action reported by the source; no additional measurement or forecast is made.

Updated:

Key figures

Measure reported by the source

Key quantitative figure stated by the source.

Unique IP addresses linked to infrastructure
≥11,000,000 count
2026-08-31 · Observed
Methodology

Value is reproduced as stated by the source; a qualifier marks an approximate or bounded figure.

Updated:

Structured coverage

Subjects and places

Subject proposals

Taxonomy version: IPTC Media Topics 2026-Q2

Continue reading