More than 11 million unique IP addresses were linked to Sality
Assessment
Europol gives the figure with no observation period, no method and no attribution to a partner. Neither CrowdStrike nor Shadowserver, the two organisations that operated sinkholes or rogue peers, has published a lifetime IP count, and Shadowserver had published nothing on the operation as of 11 September 2026. A cumulative count of unique addresses over years of dynamic allocation is not a measure of infected machines. Nothing published contradicts the figure; nothing published supports it either.
Where this claim appeared
Europol · 2026-09-02
https://www.europol.europa.eu/media-press/newsroom/news/global-public-private-operation-disrupts-sality-botnet-active-for-two-decadesWhat “Unverified” means
Widely repeated, but no supporting evidence was located. This is not a statement that the claim is false — it is a statement that nothing published supports it, which is a different and more common problem.
2 of 5 · rating scale
Assessed in
Sality Botnet Takedown: How a 23-Year-Old P2P Network Was Turned Against ItselfThink this assessment is wrong? Report an error.