Sality Botnet Dismantled After Eight Years of Crypto Hijacking
The Sality botnet, active since 2003, was dismantled after eight years of hijacking Bitcoin and Ethereum payments by replacing wallet addresses copied on infected computers. This operation, coordinated by CrowdStrike and the U.S. Department of Justice, isolated over 15,000 infected machines worldwide.
The botnet caused estimated losses of around $150,000 and left behind stolen crypto worth about $1.35 million. Although the botnet's control is disrupted, infected devices remain compromised until cleaned, marking a new phase of monitoring and removal efforts.