Global Takedown of Sality Botnet Recovers Thousands of Infected Devices
CrowdStrike and the U.S. Department of Justice announced the dismantling of the Sality peer-to-peer botnet, which had been active since 2003. The operation isolated over 15,000 infected devices globally. Over the past eight years, the botnet primarily deployed a clipboard hijacker called EggJagger, designed to steal Bitcoin and Ethereum transfers.
EggJagger monitors victims' copied crypto wallet addresses and replaces them with addresses controlled by attackers, diverting funds. CrowdStrike estimated that the tool alone stole at least $150,000 in crypto assets. Because most of the stolen funds were not moved, the portfolio's value peaked at approximately $1.35 million in January 2025.
The DOJ, FBI, and the Defense Criminal Investigative Service have seized related domains within the U.S., while police in Bulgaria, Hungary, and Romania shut down European infrastructure. Infected devices are now directed to traffic-receiving servers controlled by CrowdStrike, but the original malware remains active on the devices until manually removed.

