CrowdStrike and the U.S. Department of Justice said they have dismantled Sality, a botnet that has circulated since 2003 and spent the last eight years hijacking cryptocurrency payments by rewriting wallet addresses on infected computers.
Sality did little on its own beyond delivering other operators' payloads. For the past eight years, its main cargo was EggJagger, which CrowdStrike described as "a clipjacking tool that monitors the clipboard for cryptocurrency wallet addresses" and replaces them with the operator's own. In practice, that meant a victim copying a Bitcoin or Ethereum address for a payment could end up sending funds to a stranger.
A multinational disruption operation was announced involving the United States, Bulgaria, Hungary, and Romania, working with private-sector partners including CrowdStrike. The action was also publicized by FBI Los Angeles on September 1, 2026.
CrowdStrike said EggJagger alone generated at least 12.1 million rubles, roughly $150,000. Before EggJagger became the core payload, Sality had been used to deliver credential theft, spam, proxy services, and denial-of-service malware.
The stolen coins that were never spent
Most of the stolen cryptocurrency was left untouched. CrowdStrike said that decision ultimately proved more profitable. The firm valued the unspent portfolio at a peak of about 147 million rubles in January 2025, or a nominal $1.35 million, and said that amounted to roughly the purchasing power of $4 million in a Western capital.
Sality lasted for so long in part because it had no central server that authorities could simply seize. Infected devices communicated directly with one another, and the malware spread by attaching itself to executable files shared over network drives and removable media, allowing it to regenerate with little effort from its operator.
That same design also created an opening for defenders. Bots would accept any reachable machine that completed the handshake correctly, without verifying who was joining. CrowdStrike's Counter Adversary Operations team used that weakness to remove legitimate peers from each bot's address list and replace them with sinkholes under its control, isolating more than 15,000 machines worldwide.
In the United States, the Justice Department, FBI, and Defense Criminal Investigative Service seized Sality-linked domains. Police in Bulgaria, Hungary, and Romania took down additional domains in Europe. The Shadowserver Foundation is now working with internet providers to notify victims.
Operator tracked as SALTY SPIDER
CrowdStrike tracks the operator as SALTY SPIDER and said the botnet was sometimes used against targets chosen by the operator directly. In September 2023, a denial-of-service payload struck AvanChange, a Russian cryptocurrency exchange. CrowdStrike said the payload was compiled seconds before upload, which the firm read as an impulsive response to a personal grievance. It also said the operator likely used exchanges like AvanChange to convert stolen coins into cash.
Infected machines are now reporting to CrowdStrike-controlled sinkholes rather than to the original operator. The company has published detection rules and network indicators, but warned that malware already present on those machines remains active until it is removed.

