Sality Botnet Disrupted, but Infected PCs Still Need Cleanup

Brendan Smith
Brendan Smith - Cybersecurity Analyst
6 Min Read
Severed Sality control strings above a computer that still contains malware
The Sality disruption cuts control, but infected computers still need cleanup.

An international operation disrupted the Sality botnet on August 31, but infected Windows computers still need attention. The U.S. Department of Justice announced the action on September 1; CrowdStrike’s current report describes more than 33,000 infected machines. Cutting the operator’s command channel does not remove malware already on those PCs. If your provider or security software reports a Sality infection, verify the notice and isolate the affected device rather than assuming the takedown fixed it. [1] [2]

What the Sality operation changed

Authorities in the United States, Bulgaria, Hungary and Romania acted against Sality-linked domains. CrowdStrike and partners also disrupted its peer-to-peer network, where infected computers relay communications instead of relying on one central server. The Shadowserver Foundation is working with internet providers and incident-response teams to identify infections and support notification and remediation. [1]

CrowdStrike says the isolated bots cannot receive new payload instructions or direct payload transfers. Existing malware remains active. The operation therefore changes who can control the network; it is not a remote cleanup service for every computer. [2]

CrowdStrike map of observed Sality-infected machines across several continents
Locations of Sality-infected machines observed by CrowdStrike. This map is not a check of your own device. Source: CrowdStrike.

Who needs to act after the takedown?

Act on a verified infection notification, a Sality detection, or matching evidence identified by your IT team—not merely because you read this story. A quiet PC or an absent notification is not a clean bill of health, but neither is a slow PC proof of Sality.

Microsoft documents Sality variants that infect .exe and .scr files and spread through removable drives or network shares. That makes a folder full of “working” programs an unsafe source for restoring another computer. An autorun.inf file alone is not proof of infection. [3] General family identification belongs in our Sality file-infection and recovery reference.

What to do with a notice or detection

You received a provider or incident-response notice

Contact the provider through its known website, app or existing support number. Ask which connection and time the notice concerns, then identify the device with your IT team if several PCs share that connection. Do not install an attached “cleanup tool,” pay a verification fee, or grant remote access because an unsolicited message demands it. Preserve the original notice for investigation.

Your security tool detects Sality

Disconnect the affected PC from Wi-Fi or Ethernet and stop sharing its programs or removable drives. On a managed device, contact IT before deleting files or restarting: they may need running-process evidence. Record the complete detection name, affected paths and time. Do not restore a quarantined executable just because it is a familiar program.

An administrator is checking network evidence

CrowdStrike identifies UDP traffic to its 188.166.101[.]148 lighthouse address as infection evidence. Ask your administrator to correlate existing logs with the responsible endpoint; do not browse to or probe the address. Blocking it alone does not disinfect anything. [2]

Cleanup still needs a file-integrity decision

Removing one visible payload may leave other infected files or persistence behind. For a personal PC, a full Gridinsoft Anti-Malware scan can help identify remaining threats; review detections and investigate anything that returns after restart. Obtain tools from a trusted source and involve support if security software cannot run. A scan is not a promise to repair every modified executable or proof that no credentials were exposed.

Check for malware left after the botnet disruption

Defender can quarantine the visible file, but repeated alerts may mean a loader, scheduled task, service, browser change, or bundled component is recreating it. Scan the PC before trusting the cleanup.

Scan for remaining threats

If many unrelated programs or system files are infected, plan a trusted rebuild instead of repeatedly restoring detections. Back up essential documents separately, check them before restoration, and reinstall applications from original sources—not from the affected program folders. Our clean-install USB guide explains preparation without carrying the old installation onto the recovery media.

Use a separate clean device for account recovery and review recent payments. Before sending cryptocurrency, verify the complete destination independently, not only a copied address. Cleanup cannot reverse a completed transfer. Reconnect the PC and its storage only after the identified infection and possible reinfection sources have been addressed.

References

  1. U.S. Department of Justice. “Sality Malware Disrupted in International Cyber Takedown.” September 1, 2026. Official operation announcement.
  2. CrowdStrike Counter Adversary Operations. “Peer Pressure: Inside the Sality Botnet Disruption Operation.” September 1, 2026; accessed September 4, 2026. Technical findings and infection indicators.
  3. Microsoft Security Intelligence. “Win32/Sality.” Living threat description, accessed September 4, 2026. File infection and removable-drive behavior.
Share This Article
Cybersecurity Analyst
Follow:
Brendan Smith has spent over 15 years knee-deep in cybersecurity, chasing down malware from the gritty reverse-engineering of old-school trojans all the way to wrangling full-blown incident responses for small-to-medium businesses that couldn’t afford a full-blown breach. Over at Gridinsoft, he’s the guy piecing together those double-checked guides on nasty stuff like AsyncRAT ransomware—take last year, for instance, when his breakdowns caught more than 200 sneaky variants right in live scans, knocking user cleanup jobs down by a solid 40% and saving folks hours of headache.
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?