Don't want to trade it yourself?
Our desk runs DEX portfolios on profit share.
<img src="https://xpertsstudio.com/wp-content/uploads/2026/09/image-20.png" alt="Sality botnet dismantled after stealing Bitcoin and Ethereum through malware” loading=”lazy”>
MentionedBTC$81,150.00+4.84%ETH$2,505.28+4.61%
The Sality botnet, a malware network active since 2003, has been dismantled after spending its final eight years targeting cryptocurrency payments
CrowdStrike and the U.S. Department of Justice isolated more than 15,000 infected machines across multiple countries after disrupting the botnet’s peer-to-peer infrastructure.
The operation targeted Sality’s cryptocurrency-stealing payload, EggJagger, which monitored victims’ clipboards and replaced copied Bitcoin and Ethereum wallet addresses with addresses controlled by the attackers.
How Sality Stole Bitcoin and Ethereum
Sality primarily acted as a delivery network for other malware. During its final eight years, one of its main payloads was EggJagger, a crypto clipjacking tool designed to intercept cryptocurrency wallet addresses.
When a victim copied a Bitcoin or Ethereum address to make a payment, EggJagger could replace it with the attacker’s address.
The victim would then unknowingly send their cryptocurrency to the wrong wallet.
CrowdStrike estimates EggJagger generated at least 12.1 million rubles, roughly $150,000, in stolen cryptocurrency.
Before targeting crypto payments, Sality was used to distribute credential-stealing malware, spam tools, proxy services and denial-of-service payloads.
$1.35M in Crypto Was Left Untouched
One of the most unusual aspects of the Sality operation was what happened to the stolen cryptocurrency.
Much of the crypto was apparently never spent.
CrowdStrike estimates the stolen portfolio reached approximately 147 million rubles in January 2025, equivalent to around $1.35 million at the time.
The untouched funds helped investigators understand the scale of the operation and track the cryptocurrency connected to the malware.
Why Sality Was So Difficult to Dismantle
Sality survived for more than two decades partly because it did not depend on a traditional centralized command server.
Instead, infected computers communicated directly with one another through a peer-to-peer network.
The malware could also spread by attaching itself to executable files transferred through network shares and removable drives.
That decentralized structure made it difficult for authorities to simply seize a server and shut down the operation.
CrowdStrike’s Counter Adversary Operations team instead infiltrated the botnet’s communication system. It removed legitimate peers from infected machines’ address lists and inserted sinkholes controlled by the security firm.
More than 15,000 infected machines worldwide were subsequently isolated from the botnet’s operators.
FBI and European Authorities Seize Infrastructure
The disruption involved authorities across several countries.
The U.S. Department of Justice, FBI and Defense Criminal Investigative Service seized Sality-linked domains in the United States.
Police authorities in Bulgaria, Hungary and Romania also took action against Sality infrastructure in Europe.
The Shadowserver Foundation is working with internet service providers to notify affected users.
The operation represents a coordinated effort to disrupt both the botnet’s infrastructure and its ability to communicate with infected computers.
Sality Operator Also Targeted a Crypto Exchange
CrowdStrike tracks the suspected operator behind the activity as SALTY SPIDER.
The group did more than steal cryptocurrency through clipboard manipulation. In September 2023, a Sality-linked denial-of-service payload targeted AvanChange, a Russian cryptocurrency exchange.
CrowdStrike said the payload was compiled only seconds before it was uploaded, suggesting the attack may have been an impulsive response to a personal grievance.
The security firm also believes cryptocurrency exchanges may have been used to convert stolen assets into cash.
Infected Computers Are Still at Risk
The Sality takedown does not automatically remove the malware from affected computers.
The infected machines now communicate with CrowdStrike-controlled sinkholes rather than the botnet’s operator, but the underlying malware can remain active.
CrowdStrike has published detection rules and network indicators to help identify infections.
Users whose systems were compromised therefore still need to remove the malware rather than assuming the takedown has cleaned their machines.
Sality Takedown Highlights Crypto Malware Risks
The Sality operation shows how established malware networks can adapt to cryptocurrency.
Instead of directly attacking a crypto exchange or blockchain, EggJagger targeted one of the simplest points in the payment process: the clipboard.
A single address replacement could redirect a Bitcoin or Ethereum payment without changing the blockchain itself.
The takedown also demonstrates why decentralized malware networks can remain difficult to eliminate years after their initial deployment.
Sality may now be isolated, but infected machines remain at risk until the malware itself is removed.
Source: www.altcoinbuzz.io
