ThreatPaper
Verified

Sality has been active since 2003

Assessment

Two independent primary sources agree. Symantec's July 2011 whitepaper, written from sample analysis, states "The first public occurrence of Sality was recorded in June 2003" and describes those early versions in detail, including the strings that gave the malware its name. The Department of Justice release of 1 September 2026 states "Since 2003, the Sality botnet has installed malicious software on compromised devices." CrowdStrike and Europol give the same start year. The twenty-three-year figure in headlines follows directly.

Where this claim appeared

US Department of Justice · 2026-09-01

https://www.justice.gov/usao-cdca/pr/sality-malware-disrupted-international-cyber-takedown

What “Verified” means

Established by primary sources — the original disclosure, a vendor incident report, a court filing, a government advisory, or the affected party itself. Where a claim is material, at least two independent sources agree.

5 of 5 · rating scale

Assessed in

Sality Botnet Takedown: How a 23-Year-Old P2P Network Was Turned Against Itself

Think this assessment is wrong? Report an error.