On Tuesday, CrowdStrike and the U.S. Justice Department said they had taken down the Sality peer-to-peer botnet, a network that had been running since 2003. Decrypt reported that, over the last eight years, the botnet relied on the EggJagger malware to hijack cryptocurrency transactions. Simple trick. The malware watched victims' clipboards for wallet addresses, then swapped in the operator's own address and sent the funds to the attackers instead.
CrowdStrike said the operator stole at least 12.1 million rubles, or about $150,000, through the EggJagger payload alone. Most of that stolen cryptocurrency was never spent. And at its peak in January 2025, CrowdStrike estimated those unspent assets were worth about 147 million rubles, roughly $1.35 million. Sality lasted so long for a pretty simple reason: its decentralized design. No central server existed for authorities to grab, because infected machines talked straight to one another.
The operation spanned multiple countries, with authorities from the United States, Bulgaria, Hungary, and Romania taking part. Inside the U.S., the Justice Department, the FBI, and the Department of Defense Criminal Investigative Service seized domain names tied to Sality, while police across several European countries seized others. CrowdStrike, for its part, used weaknesses in the botnet's architecture to cut off more than 15,000 infected machines and funnel them into honeypots it controlled. And the operator, tracked under the name SALTY SPIDER, had earlier launched a denial-of-service attack on the Russian cryptocurrency exchange AvanChange in September 2023.

