Summary

  • The Justice Department and CrowdStrike announced on Tuesday the disruption of Sality, a peer-to-peer botnet active since 2003.
  • For the past eight years, its main tool was EggJagger, which altered cryptocurrency wallet addresses copied to victims' clipboards.
  • CrowdStrike estimates that the operator has stolen at least $150,000 through this method, with potential unspent holdings reaching much higher amounts.

On Tuesday, CrowdStrike and the Justice Department revealed that they have successfully dismantled Sality, a botnet that has been operational since 2003. For the last eight years, Sality has been hijacking cryptocurrency transactions by changing the wallet addresses on infected systems, according to a statement from the cybersecurity firm.

While Sality primarily served as a means to distribute other malware, its key payload was EggJagger, described by CrowdStrike as "a clipjacking tool that monitors the clipboard for cryptocurrency wallet addresses" and swaps them for the operator's own. Consequently, when a victim copies a Bitcoin or Ethereum address to make a payment, the funds are redirected to an unknown party.

A multinational effort has been launched to disrupt the botnet and associated malware known as Sality, involving actions in the United States, #Bulgaria, #Hungary, and #Romania, in collaboration with private sector partners CrowdStrike and the… pic.twitter.com/w34Bal8LG7

— FBI Los Angeles (@FBILosAngeles) September 1, 2026

CrowdStrike estimates that EggJagger alone has led to losses of at least 12.1 million rubles, approximately $150,000. Prior to EggJagger's introduction, the botnet generated income through credential theft, spam, proxy services, and denial-of-service attacks.

Unspent Stolen Cryptocurrency

The stolen cryptocurrencies were largely left unused, a decision that ultimately proved to be more lucrative. CrowdStrike estimates that the value of the unspent portfolio peaked at around 147 million rubles in January 2025, equivalent to approximately $1.35 million, or nearly $4 million in terms of purchasing power in a Western city.

Sality managed to persist since 2003 due to its decentralized structure, which lacked a central server. Infected devices communicated directly with each other, and the malware propagated by attaching itself to executable files transferred over network shares and removable drives, allowing it to regenerate effortlessly.

Myriad: What's next for Bitcoin price? Click to share your prediction.

This architecture also facilitated its entry; bots accepted any reachable device that correctly completed the handshake, with no verification on who was joining. CrowdStrike's Counter Adversary Operations team exploited this access to remove legitimate peers from each bot's address list and insert their own sinkholes, isolating over 15,000 machines worldwide.

In the U.S., the Justice Department, FBI, and Defense Criminal Investigative Service seized domains related to Sality, while law enforcement in Bulgaria, Hungary, and Romania dismantled others in Europe. The Shadowserver Foundation is collaborating with internet service providers to inform victims.

The operator, tracked by CrowdStrike as SALTY SPIDER, occasionally directed the botnet against their own targets. In September 2023, a denial-of-service attack targeted AvanChange, a Russian cryptocurrency exchange, and was compiled just before deployment, indicating an impulsive reaction to a personal issue. CrowdStrike believes the operator utilized exchanges like this to convert stolen cryptocurrencies into cash.

Infected devices now report to CrowdStrike-controlled sinkholes instead of their original operator. The company has released detection protocols and network indicators, cautioning that any malware already present on those devices will remain active until manually removed.