Skip to content
Back to Guavy Wire
Crypto

Sality Botnet Disrupted, Operator Cut Off From Infected Machines

Share

The US Justice Department has announced an international operation to disrupt the Sality botnet, used for cryptocurrency theft and other cyberattacks. The operation involved authorities in Bulgaria, Hungary, and Romania, alongside CrowdStrike and the Shadowserver Foundation.

Sality's operator had been using a clipjacking tool called EggJagger since 2003 to steal at least $150,000 in cryptocurrency over eight years. This tool monitored device clipboards for wallet addresses and replaced them with controlled addresses, allowing payments to be redirected.

The disruption severed the operator's communication with compromised machines, isolating over 15,000 infected computers from receiving new payload instructions or direct payload transfers.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc