Sality botnet dismantled after years of hijacking Bitcoin and Ethereum payments

Sality botnet dismantled after years of hijacking Bitcoin and Ethereum payments

N
News Editor
2026-09-02 11:32:37
CrowdStrike and the U.S. Department of Justice said they have disrupted Sality, a botnet that has been circulating since 2003 and spent the past eight years stealing cryptocurrency payments by swapping wallet addresses on infected computers. According to CrowdStrike, Sality mainly served as a delivery system for other malware, with EggJagger becoming its primary payload during that period. The security firm described EggJagger as a clipjacking tool that watches the clipboard for crypto wallet addresses and replaces them with addresses controlled by the operator, causing victims attempting to send Bitcoin or Ethereum to redirect funds to someone else instead. CrowdStrike estimated that EggJagger alone brought in at least 12.1 million rubles, or about $150,000. It also said most of the stolen coins were never spent, and that the untouched holdings reached a peak value of about 147 million rubles in January 2025, equal to a nominal $1.35 million. Authorities in the U.S., Bulgaria, Hungary, and Romania took part in the takedown, while CrowdStrike said it isolated more than 15,000 infected machines worldwide by redirecting them to sinkholes under its control.

CrowdStrike and the U.S. Department of Justice said they have dismantled Sality, a botnet that has circulated since 2003 and spent the last eight years hijacking cryptocurrency payments by rewriting wallet addresses on infected computers.

Sality did little on its own beyond delivering other operators' payloads. For the past eight years, its main cargo was EggJagger, which CrowdStrike described as "a clipjacking tool that monitors the clipboard for cryptocurrency wallet addresses" and replaces them with the operator's own. In practice, that meant a victim copying a Bitcoin or Ethereum address for a payment could end up sending funds to a stranger.

A multinational disruption operation was announced involving the United States, Bulgaria, Hungary, and Romania, working with private-sector partners including CrowdStrike. The action was also publicized by FBI Los Angeles on September 1, 2026.

CrowdStrike said EggJagger alone generated at least 12.1 million rubles, roughly $150,000. Before EggJagger became the core payload, Sality had been used to deliver credential theft, spam, proxy services, and denial-of-service malware.

The stolen coins that were never spent

Most of the stolen cryptocurrency was left untouched. CrowdStrike said that decision ultimately proved more profitable. The firm valued the unspent portfolio at a peak of about 147 million rubles in January 2025, or a nominal $1.35 million, and said that amounted to roughly the purchasing power of $4 million in a Western capital.

Sality lasted for so long in part because it had no central server that authorities could simply seize. Infected devices communicated directly with one another, and the malware spread by attaching itself to executable files shared over network drives and removable media, allowing it to regenerate with little effort from its operator.

That same design also created an opening for defenders. Bots would accept any reachable machine that completed the handshake correctly, without verifying who was joining. CrowdStrike's Counter Adversary Operations team used that weakness to remove legitimate peers from each bot's address list and replace them with sinkholes under its control, isolating more than 15,000 machines worldwide.

In the United States, the Justice Department, FBI, and Defense Criminal Investigative Service seized Sality-linked domains. Police in Bulgaria, Hungary, and Romania took down additional domains in Europe. The Shadowserver Foundation is now working with internet providers to notify victims.

Operator tracked as SALTY SPIDER

CrowdStrike tracks the operator as SALTY SPIDER and said the botnet was sometimes used against targets chosen by the operator directly. In September 2023, a denial-of-service payload struck AvanChange, a Russian cryptocurrency exchange. CrowdStrike said the payload was compiled seconds before upload, which the firm read as an impulsive response to a personal grievance. It also said the operator likely used exchanges like AvanChange to convert stolen coins into cash.

Infected machines are now reporting to CrowdStrike-controlled sinkholes rather than to the original operator. The company has published detection rules and network indicators, but warned that malware already present on those machines remains active until it is removed.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.