Bulgaria takes part in global operation to disrupt Sality botnet
An international operation supported by Europol and in which Bulgaria participated has disrupted the Sality peer-to-peer (P2P) botnet, a long-running criminal infrastructure used to distribute malicious payloads to thousands of infected computers worldwide, Europol said on September 2.
The coordinated action, carried out on August 31 2026 and led by United States authorities, targeted a botnet believed to have been operating for more than two decades, Europol said.
At its peak, the botnet gave its operator access to up to one million infected machines worldwide.
To date, more than 11 million unique IP addresses have been linked to the infrastructure, which could be used to distribute malicious payloads to compromised devices.
The disruption activity brought together authorities from Bulgaria, Hungary, Romania, and the US, with the support of Europol and private-sector partners CrowdStrike and the Shadowserver Foundation.
As part of the disruption, a peer-to-peer sinkholing operation was carried out to redirect communications from infected machines away from the criminal infrastructure. This isolated compromised devices from the botnet and rendered the operator’s command channel inoperable.
Unlike botnets that rely on a traditional central command-and-control server, peer-to-peer botnets such as Sality use infected machines to communicate directly with one another.
This decentralised structure makes them particularly resilient and difficult to dismantle, as disrupting individual parts of the infrastructure does not necessarily bring down the wider network, Europol said.
Tackling Sality therefore required sustained international cooperation over several years, the police cooperation agency said.
Since 2017, Europol has supported law enforcement authorities around the world in working together to identify and take down infrastructure linked to the botnet as different parts of the network were identified across jurisdictions, it said.
In the weeks leading up to the latest disruption, this cooperation intensified, with partners holding weekly operational calls to coordinate their actions. Europol supported the involvement of law enforcement authorities in Bulgaria, Hungary and Romania, helping to coordinate measures against the botnet infrastructure across the different jurisdictions.
The disruption was made possible through close cooperation between law enforcement authorities and private-sector partners, bringing together cyber intelligence, investigative capabilities and technical expertise.
Through Europol’s Cyber Intelligence Extension Programme (CIEP), CrowdStrike and the Shadowserver Foundation worked alongside law enforcement authorities, providing technical expertise and infrastructure analysis in support of the disruption.
Europol’s European Cybercrime Centre (EC3) supported the exchange and analysis of cyber intelligence, and, together with the Joint Cybercrime Action Taskforce, organised operational meetings between all the partners involved. These efforts helped establish a common operational picture of the botnet and its infrastructure, facilitate intelligence sharing among the countries involved, and ultimately develop a coordinated disruption strategy, Europol said.
(Photo: Michael Illuchine/sxc.hu)
