TL;DR
- CrowdStrike and the Department of Justice dismantled Sality, a botnet active since 2003 that operated for eight years stealing cryptocurrencies.
- The malicious tool EggJagger replaced wallet addresses in the clipboard, redirecting Bitcoin and Ethereum payments to the attacker’s accounts.
- Authorities isolated more than 15,000 infected machines across four countries; the unspent cryptocurrencies peaked at $1.35 million.
CrowdStrike and the United States Department of Justice announced the dismantling of Sality, a botnet active since 2003 that spent its last eight years intercepting cryptocurrency payments through the manipulation of wallet addresses on infected computers. The operation also involved the FBI, the Defense Criminal Investigative Service, and law enforcement agencies from Bulgaria, Hungary, and Romania.
The central mechanism of the theft was EggJagger, a tool that monitored the clipboard of each compromised machine. When a victim copied a Bitcoin or Ethereum address to make a transfer, EggJagger replaced it in real time with an address controlled by the attacker. The funds reached the thief’s hands without the user noticing any difference.
CrowdStrike estimates that through EggJagger alone, the perpetrator accumulated a minimum of 12.1 million rubles, equivalent to approximately $150,000. The stolen coins, however, were largely never spent, a decision that proved more profitable than expected: the untouched portfolio reached an estimated peak of 147 million rubles in January 2025, approximately $1.35 million at nominal value.
CrowdStrike Brought Sality Down with Its Own Architecture
Sality survived more than two decades because it operated without a central server. Infected machines communicated directly with each other, and the malware spread by attaching itself to executable files shared across local networks and removable drives. That decentralized architecture was, paradoxically, its weak point.
CrowdStrike’s Counter Adversary Operations team took advantage of the fact that the bots accepted any machine that responded correctly to the handshake protocol, without verifying the identity of the other party. Using that access, they removed legitimate peers from each bot’s contact lists and inserted their own sinkholes, isolating more than 15,000 devices worldwide.
The Department of Justice seized domains linked to Sality in the United States, while European authorities did the same in their respective jurisdictions. The Shadowserver Foundation is coordinating with internet providers to notify victims. CrowdStrike warned that the malware remains active on compromised devices until it is manually removed, and identified the operator under the tracking name SALTY SPIDER.





