Breaking
FRGermany identifies two Russian suspects in attempted attack at Leipzig airportRUFour people were killed and five were injured as a result of drone attacks by the Ukrainian Armed Forces in the DPRDEPilot makes an emergency landing with a sports plane near Schweich after an engine failureITVenice 83: opening of the Venice Film Festival with Golden Lion for Clooney and films in competitionDETwo Antonov planes set on fire at Leipzig AirportFRSwitzerland: gunshots during a rave party, at least one dead and five injured; Iceland: rejection of the referendum on the EUCRYPTO-ENBitcoin drops to $76,400 as Asian equities and bonds sell off, USD/JPY falls on BOJ intervention speculationARAl-Khanous rejects the Saudi Al-Ittihad offer of 40 million euros and decides to stay with StuttgartBRTeenager shot dead in residence after suspect celebrates crime on phoneEUEU pushes Industrial Accelerator Act to counter surge in Chinese imports threatening European industriesFRGermany identifies two Russian suspects in attempted attack at Leipzig airportRUFour people were killed and five were injured as a result of drone attacks by the Ukrainian Armed Forces in the DPRDEPilot makes an emergency landing with a sports plane near Schweich after an engine failureITVenice 83: opening of the Venice Film Festival with Golden Lion for Clooney and films in competitionDETwo Antonov planes set on fire at Leipzig AirportFRSwitzerland: gunshots during a rave party, at least one dead and five injured; Iceland: rejection of the referendum on the EUCRYPTO-ENBitcoin drops to $76,400 as Asian equities and bonds sell off, USD/JPY falls on BOJ intervention speculationARAl-Khanous rejects the Saudi Al-Ittihad offer of 40 million euros and decides to stay with StuttgartBRTeenager shot dead in residence after suspect celebrates crime on phoneEUEU pushes Industrial Accelerator Act to counter surge in Chinese imports threatening European industries
BackCrowdStrike and Justice Department dismantle Sality botnet that hijacked crypto payments for eight years
CrowdStrike and Justice Department dismantle Sality botnet that hijacked crypto payments for eight years
BREAKING
Decrypt41 minutes agoTech2 min read

CrowdStrike and Justice Department dismantle Sality botnet that hijacked crypto payments for eight years

Quick Look

CrowdStrike and the Justice Department dismantled the Sality botnet, which had operated since 2003 and spent eight years hijacking cryptocurrency payments via the EggJagger clipjacking tool, stealing at least $150,000 while leaving a peak portfolio of stolen coins valued at $1.35 million untouched.

AI-generated summary

Why It Matters

Sality botnet has been active since 2003, evolving from delivering malware payloads to specializing in cryptocurrency theft via clipboard hijacking for the past eight years.

Font size

CrowdStrike and the Justice Department have dismantled Sality, a botnet that has circulated since 2003 and spent its last eight years hijacking cryptocurrency payments by rewriting wallet addresses on infected computers, the security firm said Tuesday.

Sality itself did little beyond delivering other people's payloads. For eight years its primary cargo was EggJagger, which CrowdStrike calls "a clipjacking tool that monitors the clipboard for cryptocurrency wallet addresses" and swaps them for the operator's own. A victim copying a Bitcoin or Ethereum address to pay someone sends the money to a stranger.

CrowdStrike puts the take at a minimum of 12.1 million rubles, roughly $150,000, from EggJagger alone. Before EggJagger, the botnet earned its keep delivering credential theft, spam, proxy services and denial-of-service payloads.

What the operator never spent

The stolen coins were largely left untouched, which turned out to be the more profitable decision. CrowdStrike values the never-spent portfolio at a peak of about 147 million rubles in January 2025, a nominal $1.35 million, or roughly the purchasing power of $4 million in a Western capital.

Sality survived since 2003 because it had no central server to seize. Infected machines talked directly to one another, and the malware spread by attaching itself to executable files passed over network shares and removable drives, regenerating without effort from its operator.

That architecture was also the way in. Bots accepted any reachable machine that answered the handshake correctly, with no check on who was joining. CrowdStrike's Counter Adversary Operations team used that access to strip legitimate peers from each bot's address list and insert its own sinkholes, isolating more than 15,000 machines worldwide.

The Justice Department, FBI and Defense Criminal Investigative Service seized Sality-linked domains in the U.S., while police in Bulgaria, Hungary and Romania took down others in Europe. The Shadowserver Foundation is working with internet providers to notify victims.

The operator, whom CrowdStrike tracks as SALTY SPIDER, occasionally turned the botnet on targets of their own. A denial-of-service payload in September 2023 hit AvanChange, a Russian cryptocurrency exchange, and was compiled seconds before upload, which CrowdStrike reads as an impulsive response to a personal grievance. The firm believes the operator used exchanges like it to convert stolen coins into cash.

Infected machines now report to CrowdStrike-controlled sinkholes rather than their owner. The company has published detection rules and network indicators, and warns that malware already sitting on those machines stays active until someone removes it.

What to Watch

AI outlook — possibilities, not facts

  • CrowdStrike will release additional detection rules to help organizations identify and remove Sality infections

    Very likely · Within days

  • Infected machines will remain a threat until users manually remove the malware

    Very likely · Within weeks

Open Questions

  • What is the identity and location of the SALTY SPIDER operator?
  • Will the untouched cryptocurrency portfolio be converted to cash in the future?
  • Are there any legal proceedings planned against individuals involved?

Related Topics

This article was originally published by Decrypt.

Related Stories

TAC Network Halt Continues After Exploit Drains Bonded Staking Pool
Developing·25 minutes ago

TAC Network Halt Continues After Exploit Drains Bonded Staking Pool

The TAC network remains halted at block 24,671,475 over 10 days after an exploit drained 2,985,651,403.40 TAC (28.6% of supply) from the bonded staking pool via a balance mismatch between EVM StateDB and Cosmos SDK ledger. The attacker sold portions on BNB Chain and TON for ~1,005,774 USDT. Recovery proposes a targeted state edit to restore delegator balances using treasury reserves, but bridging and redemption remain disabled while validators await patched binary adoption.

CryptoSlate
2 min read
AI-backed group spends millions on ads to defend data centers in battleground states
Developing·2 hours ago

AI-backed group spends millions on ads to defend data centers in battleground states

Build American AI, funded by AI billionaires via super PAC Leading the Future, is spending millions on advertising in Kansas, Ohio and Wisconsin to support data center construction amid rising local opposition, which has increased to 61% nationally according to Annenberg polling, with political figures and lenders increasingly treating data center siting as a credit risk and campaign issue.

Decrypt
2 min read
Full Sail DeFi Protocol to Shut Down After Oracle Security Incident
Developing·3 hours ago

Full Sail DeFi Protocol to Shut Down After Oracle Security Incident

Full Sail, a DeFi protocol on the Sui blockchain, announced it will shut down following a security incident involving oracle provider Switchboard that led to user losses. The protocol has disabled new deposits and LP reward claims, moving regular pools to withdrawal-only mode after security checks. Full Sail will use its remaining liquidity to compensate users, with the team covering any shortfall to ensure community depositors are repaid first.

Cointelegraph
1 min read
Injective blockchain halted block production for four hours during emergency response to exploit
Developing·4 hours ago

Injective blockchain halted block production for four hours during emergency response to exploit

Injective's layer-1 blockchain stopped producing blocks for nearly four hours on Aug. 31 during an emergency response to an exploit traced to core modules. Researchers disputed the foundation's claim that the chain was 'upgraded, not halted,' noting the attack used native exchange and insurance modules. While staked funds and consensus were not compromised, the incident required a core-code patch and led to temporary validator jailing and transfer restrictions on exchanges like Coinbase and Coins.ph. INJ traded around $4.80, down 3% over 24 hours, with researchers estimating $4.9 million bridged to Ethereum during the exploit.

CryptoSlate
2 min read
More on this topicsality