CrowdStrike and the U.S. Justice Department said Tuesday they dismantled Sality, a Russia-based peer-to-peer botnet whose clipjacking payload silently swapped copied crypto wallet addresses for the operator’s own for roughly eight years. The operation spanned four countries: the U.S., Bulgaria, Hungary and Romania.
More than 15,000 infected machines were isolated in the takedown, according to CrowdStrike. The Justice Department and FBI seized Sality-linked domains inside the U.S. Police in the three European countries went after separate infrastructure.
CrowdStrike calls the payload EggJagger. It watched for a Bitcoin or Ethereum address on the victim’s clipboard, then substituted one the operator controlled. A user who copied a wallet address to send payment ended up routing funds to a stranger. CrowdStrike describes the tool as “a clipjacking tool that monitors the clipboard for cryptocurrency wallet addresses.”
Sality outlasted most of its peers. No central server existed to seize. Infected machines talked directly to one another across network shares and removable drives, regenerating on their own. Before EggJagger, the botnet cycled through credential theft, spam, proxy services and denial-of-service attacks.
The operator, tracked by CrowdStrike as SALTY SPIDER, cashed out stolen coins through exchanges including AvanChange, the firm said. CrowdStrike puts the EggJagger haul at a minimum of 12.1 million rubles, roughly $150,000. That number is a floor.
Most of the take sat untouched. The unspent portfolio was worth about 147 million rubles at its January 2025 peak. Nominally $1.35 million. In a Western capital, CrowdStrike said, the spending power runs closer to $4 million.
The takedown used the botnet’s own design against it. Sality accepted any reachable machine that answered correctly. No check on who was joining. CrowdStrike’s Counter Adversary Operations team exploited that open handshake to strip legitimate peers from each bot’s address list and insert its own sinkholes. Infected machines now report to CrowdStrike-controlled servers instead of their owner.
The Shadowserver Foundation is working with internet providers to notify victims. CrowdStrike has published detection rules and network indicators. The malware, the firm warns, stays on infected machines until someone removes it manually.
FBI Los Angeles said the operation “involving actions in the United States, Bulgaria, Hungary, and Romania, in collaboration with private industry partners CrowdStrike” was announced Monday.
The botnet’s long life shows in its side projects. A denial-of-service payload compiled seconds before upload struck AvanChange in September 2023. CrowdStrike reads the strike as impulsive, a response to a personal grievance rather than a planned attack.
The eight-year figure tracks EggJagger as the botnet’s primary payload. Sality itself goes back further. It has been active since 2003.