# Sality Was Cut Off. The Infected Computer Still Needs Cleaning

> Police and security researchers have disrupted a botnet that survived for more than two decades. Here is what that changes, what it leaves behind, and what to do if a computer is identified as infected.

- **Author:** Kubilay Tunca
- **Published:** 2026-09-02
- **Category:** For Mortals
- **Tags:** Malware, Online Safety, Windows Security
- **Canonical URL:** https://cyber-security-in-plain-english.com/post/mortals/news/sality-takedown-computer-still-needs-cleaning

---

On 31 August 2026, defenders began cutting the Sality botnet away from the computers it had infected. The operation involved US and European authorities, CrowdStrike, and the Shadowserver Foundation. It was a substantial piece of work against malware first seen in 2003. It also created an easy misunderstanding: if the botnet has been taken down, the infected computers must now be clean.

They are not automatically clean. The takedown broke the criminal's route for sending fresh instructions and malicious files through Sality's network. Software already sitting on an infected computer can remain there and keep doing whatever it was built to do. CrowdStrike says this directly in its technical account: the disruption prevents new payloads reaching infected machines, while existing malware on those systems remains active and needs to be removed.

That distinction matters more than the name of this particular virus. Police can seize a criminal website. Researchers can redirect malicious traffic. Your internet provider can warn you that a device at your address contacted a known bad system. None of those actions reaches into your computer and safely sorts every altered file, stolen password, or second piece of malware left behind. A road can be closed while the burglar is still in the house.

There is good news here. Most people do not need to spend Wednesday afternoon hunting for a 23-year-old virus. If you receive a specific infection notice, see a Sality detection, or look after a business network, however, the right response is cleanup rather than relief alone. The rest of this article explains why.

## What happened on 31 August

Sality lasted because there was no single master server that police could unplug. In a conventional botnet, infected computers may call one central machine for orders. Sality used a peer-to-peer design, so infected computers helped one another find the network. Taking out a few members did not remove the route around them, much as closing one street does not end traffic in a city with hundreds of other streets.

The coordinated operation turned that design against the botnet. According to [CrowdStrike's account of the disruption](https://www.crowdstrike.com/en-us/blog/inside-sality-botnet-disruption-operation/), each infected computer kept a list of publicly reachable infected machines called super peers. Roughly every 40 minutes, it checked which entries still answered. The defenders manipulated those lists, pushed genuine criminal peers out, and replaced them with machines under defender control, known as sinkholes. Computers that contacted the sinkholes could be isolated from the operator and counted for notification work.

Authorities also acted against web addresses that hosted files Sality had been told to download. [Reuters reported on 1 September](https://www.channelnewsasia.com/business/russian-cybercrime-operation-being-dismantled-after-two-decades-us-officials-and-crowdstrike-say-6356051) that US officials had seized domains used to control compromised computers, while CrowdStrike had cut the network away from its operator. The work involved authorities in Bulgaria, Hungary, Romania, and the United States, with Europol and Eurojust supporting the international side.

The numbers need care. CrowdStrike said the operator could distribute malicious files to more than 15,000 infected machines immediately before the disruption. [Europol's announcement on 2 September](https://www.europol.europa.eu/media-press/newsroom/news/global-public-private-operation-disrupts-sality-botnet-active-for-two-decades) said Sality had given its operator access to as many as one million infected machines at its peak, while more than 11 million unique internet addresses had been linked to its infrastructure over time. Eleven million addresses do not mean eleven million infected computers today. Home internet addresses change, several devices can share one address, and a count gathered across years measures something different from a current device count.

As of 2 September 2026, the careful description is that Sality has been disrupted and its current operator has lost the working command channel described by the investigators. David Watson of Shadowserver told Reuters that the next question was whether the still-unidentified operator would try to regain control or rebuild. That uncertainty does not diminish the operation. It simply keeps a successful intervention from becoming a fairy-tale ending.

The immediate result is valuable. An isolated Sality computer should no longer receive a fresh list of files to fetch or a malicious file sent through this peer network. The defender-controlled sinkholes also provide a way to identify connections from infected networks and pass notices toward internet providers and response teams. That buys time and information. It does not press a remote disinfect button.

## The network was removed, not the infection

Think of a botnet as two related things. The first is the infection on the computer. The second is the communication system that lets a criminal use that infection. A takedown can break the second while leaving the first physically untouched. If a thief loses the phone used to direct an accomplice inside a building, the accomplice has lost new instructions, but has not vanished.

Sality makes this separation unusually important because it is a file-infecting virus. CrowdStrike says it attached its code to Windows executable files and spread through shared folders, removable drives, and file sharing. An executable is a file that runs a program, often ending in `.exe` on Windows. Instead of living as one plainly named bad application that can be dragged to the bin, a file infector can alter programs that were already on the machine.

That is how an old infection can keep returning. Someone removes one suspicious file, then opens an infected program stored elsewhere. A cleaned computer reconnects to a shared folder containing another altered program. A USB drive moves between an old desktop and a family laptop. Sality did not need its operator to send a new phishing email each time because infected files could continue the spread locally.

The command network added another layer. Sality itself could deliver other malicious software, so a computer may contain more than Sality by the time anyone notices. Over its lifetime, the botnet distributed programs for stealing credentials, sending spam, lending out a victim's internet connection, attacking other sites, and carrying out other jobs. During the last eight years, CrowdStrike says its main delivered tool was EggJagger, which watched for cryptocurrency wallet addresses copied to the clipboard and silently replaced them with an address controlled by the operator.

That clipboard trick is wonderfully mundane. Imagine copying the destination for a payment, pasting it into a wallet, and checking only that a long jumble of letters appeared. The pasted address looks like the thing you copied because both are long and unfamiliar. According to CrowdStrike, the operator stole at least 12.1 million roubles, about $150,000 at the stated exchange value, through this method. The estimate covers that payload, not every possible way the botnet earned money.

Once the Sality command route is cut, it cannot send a new copy of EggJagger through that route. An EggJagger copy already installed does not depend on a new delivery to watch the clipboard today. The same principle applies to a password stealer that already ran, a hidden remote-access tool that established its own channel, or an account password copied last month. Cutting the delivery van off at the motorway does not recall parcels already dropped at the house.

For an ordinary computer owner, this is the central lesson. A successful takedown changes what the criminal can do next through the disrupted network. Cleanup deals with what has already happened on the device and in the accounts reachable from it. Both jobs matter, and they belong to different people.

## Who should act, and who can carry on

A worldwide number can make any Windows user wonder whether their laptop is one of the infected machines. The available reports do not support that leap. Sality has circulated for decades, yet the current operation concerns a specific set of computers communicating through its peer networks. No public source cited here says every Windows user should assume infection or replace a computer.

A specific notice changes the calculation. Shadowserver is working with internet providers and national response teams to identify networks connecting to the sinkholes, according to [Help Net Security's 2 September report](https://www.helpnetsecurity.com/2026/09/02/sality-botnet-disruption-crowdstrike-law-enforcement/). Such a notice may come from your internet provider, your employer, a school, or the person who manages a business network. Treat it as a useful smoke alarm. Verify the notice through contact details you find yourself before following links or calling numbers inside an unexpected message.

A named antivirus detection deserves action too. Microsoft has long detected Sality under names beginning with `Virus:Win32/Sality`, and other security products use their own labels. A detection history entry on the computer is stronger evidence than a news headline. Repeated warnings after removal, security software that will not run, programs behaving strangely, or an external drive that seems to reinfect machines are also reasons to stop and investigate.

Businesses have a more direct technical clue. CrowdStrike published a defender-controlled internet address and recent download addresses in its report, and said traffic to the sinkhole address confirms an active Sality infection. A network administrator can look for that traffic in firewall, DNS, endpoint, or other connection records. A home user should not be expected to interpret raw network logs. Your provider or a reputable repair professional can translate a notice into the device check that matters.

Without a notice, detection, or symptom, keep the response proportionate. Install current operating-system and security updates, make sure real-time protection is on, and let your normal antivirus scan as usual. Those are worthwhile habits whether Sality exists or not. Downloading a mystery "Sality cleaner" from a search advert introduces a fresh risk in the name of fixing a risk you have not established.

Cryptocurrency users have one extra reason to pay attention to a confirmed infection, because the reported clipboard replacement was designed for wallet addresses. Anyone sending a transaction should already compare the destination shown by the wallet with the destination supplied by the recipient, especially the beginning and end, using a separate trusted route when the amount matters. If a machine is suspected of infection, do not use it for a payment at all. Move to a known-clean device and investigate first.

The calm position is simple. News alone calls for awareness. Evidence on your network or computer calls for cleanup. You are allowed to skip the dramatic scanner adverts in between.

## What a proper cleanup has to cover

Disconnecting a suspected computer from the network is a sensible first move. Turn off Wi-Fi or unplug its network cable, but leave the machine powered on if a workplace incident-response team has asked you to preserve it. For a family computer with no professional responder involved, the aim is to stop more communication and stop the same removable drive carrying altered files to another computer while you decide what to do.

Use a different, known-clean phone or computer for research and account changes. A machine suspected of stealing passwords should not be trusted with a new password. Start with the email account that can reset other accounts, then financial services, shopping accounts with stored payment details, and any work login used on the computer. Change only accounts that could reasonably have been exposed, enable two-factor authentication where it is offered, and look for unfamiliar recovery addresses, forwarding rules, devices, or sessions.

The computer itself needs a current security scan. Update the security tool's definitions first if that can be done safely, then run a full scan rather than the quick check intended for routine daily use. If Windows Security reports that an offline scan is needed, or a detection returns after an ordinary cleanup, Microsoft provides a scan that restarts the computer and checks it from outside the normal Windows session. [Microsoft's current instructions for Defender Offline](https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-offline) place it under Windows Security, Virus and threat protection, Scan options, Microsoft Defender Offline scan.

An offline scan has a practical advantage: malware running inside Windows gets fewer opportunities to hide or interfere. It is still a scanner, not a promise that every altered file has been restored perfectly. Microsoft's instructions also warn that a computer protected with BitLocker may ask for its recovery key during the restart, so find that key before beginning. On a work machine, let the support team handle this rather than improvising around company encryption.

Confirmed Sality deserves more caution than one disposable browser extension because of its file-infecting behaviour. Back up irreplaceable documents, photographs, and other personal data, but avoid copying programs, installers, screen savers, or scripts from the infected machine into the backup. Those executable files are exactly where a file infector may travel. Keep the backup separate until the computer and the stored files have been checked.

For a lightly used home computer, a clean reinstall from trusted Windows installation media may be less uncertain than trying to repair a large collection of altered programs one by one. For a business computer, the safer route is often to reimage it using the organisation's known-good build, then restore approved data and applications. A technician should make that call with the evidence in front of them. The important point is that clicking "quarantine" once may be only the beginning when the virus can be woven into other files.

Shared locations need attention as well. Check USB drives, external disks, old network folders, and other Windows computers that exchanged programs with the infected one. Do not plug a suspect drive into the family laptop simply to see what is on it. A repair shop or IT team can examine it with protective settings and scan tools in place. Documents and photographs matter; an old folder of downloaded installers can usually be replaced from the software maker.

When the machine is rebuilt or declared clean, reconnect it carefully. Run updates again, install applications from their real publishers, restore data rather than old program files, and watch the security history for a return. Review bank and email activity for a while because cleaning the computer cannot unsteal a password or reverse a payment already sent. The house needs cleaning, then the copied keys need replacing.

## A practical sequence if you receive a Sality notice

A notice arriving from an internet provider can be alarming because it may identify only the household connection, not the device. Several phones, televisions, laptops, consoles, and work machines can share one public internet address. Sality's documented targets are Windows executables, so begin with Windows computers and any removable storage moved among them rather than resetting every connected gadget.

The sequence below is deliberately short enough to follow under stress. It assumes this is a home or very small-business device without a formal response team. If an employer owns the computer, stop at the first step and call the employer's support contact from another device.

1. **Verify the warning through a separate route.** Open your provider's official app or type its website address yourself. Call the number on a bill if needed. Do not install software from a link in the warning until you know the message is genuine.

2. **Separate the suspected computer.** Turn off its Wi-Fi or unplug the network cable. Put aside USB drives and external disks used with it. Do not move those drives to another computer for convenience.

3. **Protect important accounts from a clean device.** Change the email password first if it was used on the suspect machine, sign out unfamiliar sessions, and check recovery details. Continue with banking, cryptocurrency, work, and shopping accounts according to what that computer could access.

4. **Record what you know.** Photograph the warning or security detection, note the date, and write down the product's exact malware name. For a business, preserve relevant logs and contact the person responsible for IT or security before deleting evidence.

5. **Scan, then make a rebuild decision.** Update a reputable security tool and run a full scan. Follow a request for an offline scan. If Sality is confirmed, returns, has disabled security tools, or has infected many programs, ask a reputable technician about reinstalling Windows from trusted media rather than assuming every file can be repaired safely.

6. **Check the paths by which it can return.** Scan or replace removable drives and shared program folders. Reinstall applications from the publisher instead of restoring old installers. Check other Windows machines that ran the same copied software.

7. **Reconnect and observe.** Install all updates, confirm protection is running, and review account and payment activity. Ask the provider whether it still sees infected traffic after its reporting delay. Keep the record of what was changed in case the warning returns.

You do not need to become a malware analyst to follow that path. You need a clean device for the sensitive steps, a clear separation between personal data and old programs, and enough patience to check the other places an infected executable may have reached. If a trusted professional is available, paying for one careful cleanup is better than downloading five hopeful tools from five unfamiliar sites.

## What the takedown teaches beyond Sality

Sality survived for more than two decades partly because its communication network had no obvious head to remove. The very feature that gave it resilience also gave defenders a repeated ritual they could study: each member refreshed a finite list of peers on a schedule. Years of reverse engineering turned that maintenance process into a route for replacing criminal peers with sinkholes. According to Reuters, CrowdStrike researcher Tillmann Werner called it the most complex botnet takeover the company had done.

That mechanism matters because the word "takedown" can hide many different outcomes. Sometimes police seize a server and display a banner. Sometimes a court order transfers a domain. Here, researchers spoke the botnet's own peer-to-peer language, altered the lists through which infected machines found one another, and worked with authorities to remove file-hosting addresses at the same time. The result was a communication cutoff plus a continuing view of infected systems as they called the sinkholes.

A sinkhole is closer to call forwarding than to a cleaning service. Traffic meant for the criminal arrives at a system controlled by defenders. They can count it, study it within legal and privacy limits, and pass useful warnings toward the network owner. The infected computer has revealed itself, but the sinkhole usually cannot rewrite every file or know which accounts were used from that machine.

The case also shows why old technology does not become harmless merely because newer criminals prefer ransomware headlines. Sality first appeared when Windows XP was current. Its peer networks remained useful in 2026 because infected machines still provided access, traffic, computing time, and opportunities to deliver newer software. Old malware can remain commercially useful when old systems, forgotten installers, and shared drives continue to circulate.

For families, the lesson is not to catalogue malware names. Keep supported computers updated, leave reputable security protection running, treat unexpected infection notices as claims to verify, and know how you would recover the files that matter. For small businesses, add ownership: someone must receive provider notices, know which device used an address at a given time, and have a tested way to rebuild a machine without restoring the infection with it.

Takedowns and personal hygiene meet in the middle. Investigators can close the road. Internet providers can point to the address. The device owner or support team still has to check the rooms, remove what was left, and replace keys that may have been copied.

## The useful good news

A criminal who could send fresh files to thousands of infected computers lost that route on 31 August 2026. Defenders gained a way to see connections from those infections and help notify the networks involved. Authorities in several countries coordinated the technical and legal work needed to act at the same time. Those are concrete gains, not public-relations theatre.

The limits are equally concrete. Sality code and other delivered malware can remain on infected computers. Accounts and cryptocurrency taken before the cutoff do not restore themselves. The unidentified operator may try to recover or build again, which is why Reuters and Shadowserver framed the aftermath as something to watch rather than a closed history book.

If you have no notice and no detection, keep your computer updated and carry on. If you do receive a verified warning, disconnect the affected machine, use a clean device to protect important accounts, and treat a confirmed file infection as a reason for a thorough scan or clean rebuild. You can ignore the dramatic cleaner adverts. Spend your effort on the computer the evidence actually points to.

The larger habit is worth keeping after Sality leaves the news. A disrupted criminal network is safer than a working one, but a silent computer is not necessarily a clean one. Recovery ends when the device, the files it shared, and the accounts it could reach have all been considered.

If you want calm, practical security guidance without a daily alarm bell, join the newsletter. It is one email per month.

## Sources

- [CrowdStrike: Peer Pressure, Inside the Sality Botnet Disruption Operation](https://www.crowdstrike.com/en-us/blog/inside-sality-botnet-disruption-operation/), accessed 2026-09-02
- [Europol: Global public-private operation disrupts Sality botnet active for two decades](https://www.europol.europa.eu/media-press/newsroom/news/global-public-private-operation-disrupts-sality-botnet-active-for-two-decades), accessed 2026-09-02
- [Reuters via CNA: Russian cybercrime operation being dismantled after two decades, US officials and CrowdStrike say](https://www.channelnewsasia.com/business/russian-cybercrime-operation-being-dismantled-after-two-decades-us-officials-and-crowdstrike-say-6356051), accessed 2026-09-02
- [Help Net Security: Global sinkhole operation ends Sality botnet's 23-year run](https://www.helpnetsecurity.com/2026/09/02/sality-botnet-disruption-crowdstrike-law-enforcement/), accessed 2026-09-02
- [Microsoft Learn: Microsoft Defender Offline scan in Windows](https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-offline), accessed 2026-09-02

---

## About the author

Kubilay Tunca — Senior Full Stack Developer and Author. Founded Cyber Security in Plain English to translate complex security concepts into clear, practical advice, and writes the accompanying books on security, privacy, secure development, and AI systems.

## Books by this author

- **The Digital Fortress** — Your Everyday Guide to a Safer Digital Life. A warm, plain-English guide for people with real lives and finite patience. Learn the handful of habits that genuinely protect your money, accounts, and family, and get honest permission to ignore the rest. [Amazon](https://buy.cyber-security-in-plain-english.com/digital-fortress) · [Details](https://cyber-security-in-plain-english.com/books/the-digital-fortress)
- **The Anonymity Playbook** — Digital Survival for Whistleblowers, Journalists, Activists, and Everyone Else. A practitioner’s field manual for journalists protecting sources, whistleblowers, and activists. It explains how the surveillance actually works, what each technique costs you, and exactly where it fails. [Amazon](https://buy.cyber-security-in-plain-english.com/anonymity-playbook) · [Details](https://cyber-security-in-plain-english.com/books/the-anonymity-playbook)
- **Secure Software Development** — Practical patterns for building secure software. A hands-on security guide for developers and IT professionals who ship real software. Build, deploy, and maintain secure systems without slowing down or drowning in theory. [Amazon](https://buy.cyber-security-in-plain-english.com/secure-software-development) · [Details](https://cyber-security-in-plain-english.com/books/secure-software-development)
- **The Secure Harness** — Shipping Production Code with AI Coding Agents. A calm, practical guide to letting agents do useful work inside boundaries you set, enforce, and audit. Ships with 15 copy-pasteable artifacts: hook scripts, permission configs, release gates, and MCP templates. [Amazon](https://buy.cyber-security-in-plain-english.com/secure-harness) · [Details](https://cyber-security-in-plain-english.com/books/the-secure-harness)
- **The AI Native Engineer** — Build, Evaluate, and Ship AI Systems That Work in Production. Sixteen hands-on chapters, one real product. Grow it from a single model call into a retrieved, tool-using, observable, production-grade system, with evaluation treated as a habit from the first feature. [Amazon](https://buy.cyber-security-in-plain-english.com/ai-native-engineer) · [Details](https://cyber-security-in-plain-english.com/books/the-ai-native-engineer)

Full catalogue with contents and intended audience: https://cyber-security-in-plain-english.com/books

_As an Amazon Associate I earn from qualifying purchases. Buying through these links costs you nothing extra and helps pay for the blog._
