CrowdStrike and Justice Department dismantle Sality botnet that hijacked crypto payments for eight years
Quick Look
CrowdStrike and the Justice Department dismantled the Sality botnet, which had operated since 2003 and spent eight years hijacking cryptocurrency payments via the EggJagger clipjacking tool, stealing at least $150,000 while leaving a peak portfolio of stolen coins valued at $1.35 million untouched.
AI-generated summary
Why It Matters
Sality botnet has been active since 2003, evolving from delivering malware payloads to specializing in cryptocurrency theft via clipboard hijacking for the past eight years.
CrowdStrike and the Justice Department have dismantled Sality, a botnet that has circulated since 2003 and spent its last eight years hijacking cryptocurrency payments by rewriting wallet addresses on infected computers, the security firm said Tuesday.
Sality itself did little beyond delivering other people's payloads. For eight years its primary cargo was EggJagger, which CrowdStrike calls "a clipjacking tool that monitors the clipboard for cryptocurrency wallet addresses" and swaps them for the operator's own. A victim copying a Bitcoin or Ethereum address to pay someone sends the money to a stranger.
CrowdStrike puts the take at a minimum of 12.1 million rubles, roughly $150,000, from EggJagger alone. Before EggJagger, the botnet earned its keep delivering credential theft, spam, proxy services and denial-of-service payloads.
What the operator never spent
The stolen coins were largely left untouched, which turned out to be the more profitable decision. CrowdStrike values the never-spent portfolio at a peak of about 147 million rubles in January 2025, a nominal $1.35 million, or roughly the purchasing power of $4 million in a Western capital.
Sality survived since 2003 because it had no central server to seize. Infected machines talked directly to one another, and the malware spread by attaching itself to executable files passed over network shares and removable drives, regenerating without effort from its operator.
That architecture was also the way in. Bots accepted any reachable machine that answered the handshake correctly, with no check on who was joining. CrowdStrike's Counter Adversary Operations team used that access to strip legitimate peers from each bot's address list and insert its own sinkholes, isolating more than 15,000 machines worldwide.
The Justice Department, FBI and Defense Criminal Investigative Service seized Sality-linked domains in the U.S., while police in Bulgaria, Hungary and Romania took down others in Europe. The Shadowserver Foundation is working with internet providers to notify victims.
The operator, whom CrowdStrike tracks as SALTY SPIDER, occasionally turned the botnet on targets of their own. A denial-of-service payload in September 2023 hit AvanChange, a Russian cryptocurrency exchange, and was compiled seconds before upload, which CrowdStrike reads as an impulsive response to a personal grievance. The firm believes the operator used exchanges like it to convert stolen coins into cash.
Infected machines now report to CrowdStrike-controlled sinkholes rather than their owner. The company has published detection rules and network indicators, and warns that malware already sitting on those machines stays active until someone removes it.
What to Watch
AI outlook — possibilities, not facts
CrowdStrike will release additional detection rules to help organizations identify and remove Sality infections
Very likely · Within days
Infected machines will remain a threat until users manually remove the malware
Very likely · Within weeks
Open Questions
- What is the identity and location of the SALTY SPIDER operator?
- Will the untouched cryptocurrency portfolio be converted to cash in the future?
- Are there any legal proceedings planned against individuals involved?







