The U.S. Department of Justice, FBI, Defense Criminal Investigative Service and CrowdStrike have disrupted the Sality botnet, a peer-to-peer network active since 2003 that spent the past eight years distributing the EggJagger clipboard-hijacking malware. The multinational operation involved actions in the United States, Bulgaria, Hungary and Romania.
According to CrowdStrike, EggJagger monitored victims’ clipboards for cryptocurrency wallet addresses and silently replaced them with addresses controlled by the operator, redirecting Bitcoin and Ethereum payments from infected machines. The firm estimates the payload stole at least 12.1 million rubles, roughly $150,000, while the unspent stolen portfolio peaked at about 147 million rubles in January 2025, nominally around $1.35 million.
Because Sality had no central command-and-control server, infected machines talked directly to one another. CrowdStrike’s Counter Adversary Operations team exploited that design by removing legitimate peers from bot address lists and inserting its own sinkholes, isolating more than 15,000 machines worldwide. The Shadowserver Foundation is working with internet providers to notify victims.
CrowdStrike tracks the operator as SALTY SPIDER, and said the group occasionally used the botnet for personal grievances, including a September 2023 denial-of-service attack on the Russian cryptocurrency exchange AvanChange. The takedown severs operator control, but CrowdStrike warned that malware already installed on compromised systems remains active until removed.