CrowdStrike Takes Down Botnet that Stole Millions in Crypto
US cybersecurity firm CrowdStrike and federal authorities have dismantled Sality, a botnet that has been operating since 2003. The malware spent its last eight years hijacking cryptocurrency payments on infected computers. Its main payload, 'EggJagger,' watched the clipboard for wallet addresses and replaced them with ones belonging to the attackers.
The attack is simple but effective: most users copy-paste wallet addresses instead of typing them in manually. This allows EggJagger to intercept the transaction and send it to the attacker's address instead.
CrowdStrike estimated that the attackers stole at least 12.1 million rubles, or around $150,000, over eight years. However, much of the crypto was left untouched and its value rose as high as $1.35 million in early 2025 due to rising crypto prices.
The operation to dismantle Sality involved replacing the peer addresses with CrowdStrike's own servers, cutting off more than 15,000 infected machines from the network.