Russian Botnet Sality Shut Down After Two Decades of Crypto Theft
After a two-decade run, Russian crypto-stealing botnet Sality has been shut down in collaboration with CrowdStrike and US federal authorities.
The botnet's primary operation from 2017 to 2025 involved clipboard hijacking, where it monitored users' clipboard activity on infected systems. Whenever a user copied a cryptocurrency wallet address, the malware substituted it with an attacker-controlled wallet, allowing the criminals to steal digital assets from unsuspecting victims.
According to CrowdStrike's analysis, EggJagger was the primary weapon in this operation, constantly surveilling clipboard data for cryptocurrency addresses and replacing them with fraudulent ones. The infection vector relied on shared network resources and removable storage devices, embedding itself within legitimate applications and maintaining persistence through self-replication mechanisms.
The decentralized architecture of Sality enabled infected systems to communicate directly with one another, complicating takedown efforts. However, researchers identified a vulnerability in the peer-to-peer communication protocol, substituting legitimate peer addresses with company-controlled infrastructure to isolate over 15,000 infected devices from the criminal network.