Sality Botnet Dismantled After Eight Years of Cryptocurrency Heists
A notorious botnet that has been circulating since 2003 has finally been dismantled by CrowdStrike and the Justice Department. Sality, as it's known, spent its last eight years hijacking cryptocurrency payments by rewriting wallet addresses on infected computers.
The botnet itself didn't engage in any malicious activity beyond delivering payloads from other attackers. For most of these eight years, it carried a tool called EggJagger, which monitored the clipboard for cryptocurrency wallet addresses and swapped them with the operator's own address. This allowed the attacker to intercept payments meant for others.
CrowdStrike estimates that Sality earned at least 12.1 million rubles (about $150,000) from EggJagger alone. However, the stolen coins were largely left untouched by the operator, who valued the never-spent portfolio at a peak of about 147 million rubles in January 2025.
The botnet's decentralized architecture made it difficult to shut down, but CrowdStrike was able to exploit this design and strip legitimate peers from each bot's address list. The security firm inserted its own sinkholes, isolating over 15,000 machines worldwide.