Server racks at a data centre in Amravati (archive).
Server racks at a data centre in Amravati (archive). Illustrative archive image; not a photograph of the reported 2026 event. Image: PiDatacenters / Wikimedia Commons, CC BY-SA 4.0. Resized and converted to JPEG; thumbnails may be cropped by the page layout.

An international operation disrupted the Sality botnet on 31 August, Europol announced on 2 September. The US-led action brought together authorities in Bulgaria, Hungary and Romania, with Europol and private-sector partners supporting the effort against infrastructure active for more than two decades.

Europol said more than 11 million unique IP addresses had been associated with the network over time. That cumulative figure is not a count of machines simultaneously infected during the operation. The action interrupted the operator's ability to communicate with compromised devices. Sality's peer-to-peer structure had made it difficult to dismantle, demonstrating the persistence of older malware infrastructure. Disrupting control is an important intervention, but affected devices can still require assessment and remediation.