Europol-backed operation targets Sality botnet infrastructure
Europol said an international action on 31 August targeted Sality botnet infrastructure linked to more than 11 million unique IP addresses.
Event / data period: 2026-08-31
Published: · Updated:
Europol announced on 2 September 2026 a coordinated action led by US authorities with Bulgaria, Hungary and Romania. It said the Sality peer-to-peer botnet had been used for years to distribute malicious payloads and that more than 11 million unique IP addresses had been linked to its infrastructure.
At its peak, the botnet was believed to have given its operator access to as many as one million infected machines worldwide, according to Europol. The European Cybercrime Centre supported intelligence sharing and operational meetings; the reported IP-address total does not represent a count of infected devices.
Data
Security development
Security event or institutional action reported by the source.
- · Occurred
Coordinated action against the Sality botnet
The US-led action targeted the botnet infrastructure with Bulgaria, Hungary and Romania. Europol said more than 11 million unique IP addresses had been linked to the infrastructure.
Methodology
The event date and description summarise the action reported by the source; no additional measurement or forecast is made.
Updated:
Measure reported by the source
Key quantitative figure stated by the source.
- Unique IP addresses linked to infrastructure
- ≥11,000,000 count
- 2026-08-31 · Observed
Methodology
Value is reproduced as stated by the source; a qualifier marks an approximate or bounded figure.
Updated:
Subjects and places
Subject proposals
- Cyber crimeSuggested
- Subject suggested from the title or summary: botnetwww.europol.europa.eu ↗