US Authorities Dismantle Decades-Old Sality Botnet with Crowdsrike
US authorities have joined forces with cybersecurity firm CrowdStrike to dismantle the Sality botnet, which has been active since 2003. The botnet has primarily used EggJagger malware to steal cryptocurrency payments over the past eight years.
CrowdStrike estimates that operators of the botnet have stolen at least $1.5 million in cryptocurrency through this method alone.
The affected funds are largely untouched, with CrowdStrike valuing them at around $14.7 million at their peak in January 2025.
The botnet's longevity is attributed to its decentralized architecture, which lacks a central server that can be seized by authorities. However, this effort involved multiple countries and saw US law enforcement seize related domains within the country, as well as similar actions taken by European authorities.