CrowdStrike and US Justice Department Dismantle Sality Botnet That Hijacked Crypto Payments

CrowdStrike and US Justice Department Dismantle Sality Botnet That Hijacked Crypto Payments

N
News Editor
2026-09-02 11:39:43
CrowdStrike, in coordination with the U.S. Justice Department, announced Tuesday the takedown of the Sality peer-to-peer botnet, which had been active since 2003. Over the past eight years, it used the EggJagger malware to hijack cryptocurrency payments, stealing at least 12.1 million rubles (approximately $150,000). Unspent stolen crypto was valued at around 147 million rubles (roughly $1.35 million) at its peak in January 2025. The operation involved authorities from the U.S., Bulgaria, Hungary, and Romania. CrowdStrike isolated over 15,000 infected machines into honeypots. The operator, tracked as SALTY SPIDER, previously launched a DDoS attack on Russian exchange AvanChange in September 2023.

On Tuesday, CrowdStrike and the U.S. Justice Department said they had taken down the Sality peer-to-peer botnet, a network that had been running since 2003. Decrypt reported that, over the last eight years, the botnet relied on the EggJagger malware to hijack cryptocurrency transactions. Simple trick. The malware watched victims' clipboards for wallet addresses, then swapped in the operator's own address and sent the funds to the attackers instead.

CrowdStrike said the operator stole at least 12.1 million rubles, or about $150,000, through the EggJagger payload alone. Most of that stolen cryptocurrency was never spent. And at its peak in January 2025, CrowdStrike estimated those unspent assets were worth about 147 million rubles, roughly $1.35 million. Sality lasted so long for a pretty simple reason: its decentralized design. No central server existed for authorities to grab, because infected machines talked straight to one another.

The operation spanned multiple countries, with authorities from the United States, Bulgaria, Hungary, and Romania taking part. Inside the U.S., the Justice Department, the FBI, and the Department of Defense Criminal Investigative Service seized domain names tied to Sality, while police across several European countries seized others. CrowdStrike, for its part, used weaknesses in the botnet's architecture to cut off more than 15,000 infected machines and funnel them into honeypots it controlled. And the operator, tracked under the name SALTY SPIDER, had earlier launched a denial-of-service attack on the Russian cryptocurrency exchange AvanChange in September 2023.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.