An international operation disrupted the Sality botnet on August 31, but infected Windows computers still need attention. The U.S. Department of Justice announced the action on September 1; CrowdStrike’s current report describes more than 33,000 infected machines. Cutting the operator’s command channel does not remove malware already on those PCs. If your provider or security software reports a Sality infection, verify the notice and isolate the affected device rather than assuming the takedown fixed it. [1] [2]
What the Sality operation changed
Authorities in the United States, Bulgaria, Hungary and Romania acted against Sality-linked domains. CrowdStrike and partners also disrupted its peer-to-peer network, where infected computers relay communications instead of relying on one central server. The Shadowserver Foundation is working with internet providers and incident-response teams to identify infections and support notification and remediation. [1]
CrowdStrike says the isolated bots cannot receive new payload instructions or direct payload transfers. Existing malware remains active. The operation therefore changes who can control the network; it is not a remote cleanup service for every computer. [2]

Who needs to act after the takedown?
Act on a verified infection notification, a Sality detection, or matching evidence identified by your IT team—not merely because you read this story. A quiet PC or an absent notification is not a clean bill of health, but neither is a slow PC proof of Sality.
Microsoft documents Sality variants that infect .exe and .scr files and spread through removable drives or network shares. That makes a folder full of “working” programs an unsafe source for restoring another computer. An autorun.inf file alone is not proof of infection. [3] General family identification belongs in our Sality file-infection and recovery reference.
What to do with a notice or detection
You received a provider or incident-response notice
Contact the provider through its known website, app or existing support number. Ask which connection and time the notice concerns, then identify the device with your IT team if several PCs share that connection. Do not install an attached “cleanup tool,” pay a verification fee, or grant remote access because an unsolicited message demands it. Preserve the original notice for investigation.
Your security tool detects Sality
Disconnect the affected PC from Wi-Fi or Ethernet and stop sharing its programs or removable drives. On a managed device, contact IT before deleting files or restarting: they may need running-process evidence. Record the complete detection name, affected paths and time. Do not restore a quarantined executable just because it is a familiar program.
An administrator is checking network evidence
CrowdStrike identifies UDP traffic to its 188.166.101[.]148 lighthouse address as infection evidence. Ask your administrator to correlate existing logs with the responsible endpoint; do not browse to or probe the address. Blocking it alone does not disinfect anything. [2]
Cleanup still needs a file-integrity decision
Removing one visible payload may leave other infected files or persistence behind. For a personal PC, a full Gridinsoft Anti-Malware scan can help identify remaining threats; review detections and investigate anything that returns after restart. Obtain tools from a trusted source and involve support if security software cannot run. A scan is not a promise to repair every modified executable or proof that no credentials were exposed.
Defender can quarantine the visible file, but repeated alerts may mean a loader, scheduled task, service, browser change, or bundled component is recreating it. Scan the PC before trusting the cleanup.
Scan for remaining threatsIf many unrelated programs or system files are infected, plan a trusted rebuild instead of repeatedly restoring detections. Back up essential documents separately, check them before restoration, and reinstall applications from original sources—not from the affected program folders. Our clean-install USB guide explains preparation without carrying the old installation onto the recovery media.
Use a separate clean device for account recovery and review recent payments. Before sending cryptocurrency, verify the complete destination independently, not only a copied address. Cleanup cannot reverse a completed transfer. Reconnect the PC and its storage only after the identified infection and possible reinfection sources have been addressed.
References
- U.S. Department of Justice. “Sality Malware Disrupted in International Cyber Takedown.” September 1, 2026. Official operation announcement.
- CrowdStrike Counter Adversary Operations. “Peer Pressure: Inside the Sality Botnet Disruption Operation.” September 1, 2026; accessed September 4, 2026. Technical findings and infection indicators.
- Microsoft Security Intelligence. “Win32/Sality.” Living threat description, accessed September 4, 2026. File infection and removable-drive behavior.

