Sality Botnet Dismantled After Eight Years of Crypto Heists
The Sality botnet has been dismantled after eight years of stealing Bitcoin and Ethereum. The Justice Department, CrowdStrike, and international law enforcement agencies collaborated to disrupt the malware, which had circulated since 2003.
For the past eight years, Sality's primary payload was EggJagger, a clipjacking tool that replaced cryptocurrency wallet addresses copied by victims with the operator's own. This allowed the operator to steal at least $150,000 from infected machines, with the unspent holdings peaking at around $4 million in January 2025.
CrowdStrike estimates that over 15,000 machines worldwide were infected with Sality. The botnet's architecture made it difficult to track and dismantle, but CrowdStrike's Counter Adversary Operations team was able to strip legitimate peers from each bot's address list and insert sinkholes, isolating the infected machines.
The Justice Department and law enforcement agencies in Bulgaria, Hungary, and Romania seized Sality-linked domains, while the Shadowserver Foundation worked with internet providers to notify victims. The operator, known as SALTY SPIDER, occasionally targeted specific exchanges, including a denial-of-service payload against AvanChange in September 2023.