Sality Botnet Dismantled After Eight Years of Crypto Theft

1 hour ago 3 sources positive

Key takeaways:

  • Clipboard malware risks persist despite botnet takedowns; hardware wallets remain essential defense.
  • Modest $150k theft suggests crypto crime shifts to lower-volume, harder-to-trace wallet swaps.
  • Cross-border DOJ-FBI action signals rising regulatory enforcement against crypto-targeting cybercrime infrastructure.

The U.S. Department of Justice, FBI, Defense Criminal Investigative Service and CrowdStrike have disrupted the Sality botnet, a peer-to-peer network active since 2003 that spent the past eight years distributing the EggJagger clipboard-hijacking malware. The multinational operation involved actions in the United States, Bulgaria, Hungary and Romania.

According to CrowdStrike, EggJagger monitored victims’ clipboards for cryptocurrency wallet addresses and silently replaced them with addresses controlled by the operator, redirecting Bitcoin and Ethereum payments from infected machines. The firm estimates the payload stole at least 12.1 million rubles, roughly $150,000, while the unspent stolen portfolio peaked at about 147 million rubles in January 2025, nominally around $1.35 million.

Because Sality had no central command-and-control server, infected machines talked directly to one another. CrowdStrike’s Counter Adversary Operations team exploited that design by removing legitimate peers from bot address lists and inserting its own sinkholes, isolating more than 15,000 machines worldwide. The Shadowserver Foundation is working with internet providers to notify victims.

CrowdStrike tracks the operator as SALTY SPIDER, and said the group occasionally used the botnet for personal grievances, including a September 2023 denial-of-service attack on the Russian cryptocurrency exchange AvanChange. The takedown severs operator control, but CrowdStrike warned that malware already installed on compromised systems remains active until removed.

Previously on the topic:
Aug 31, 2026, 1:28 p.m.
FBI and Australian Police Dismantle Global Crypto Laundering Network
Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.