TLDR
- CrowdStrike and federal law enforcement shut down Sality, a Russia-based botnet active since 2003
- The malware used a tool called EggJagger to swap copied crypto wallet addresses with attacker-controlled ones
- Around $150,000 in Bitcoin and Ethereum was stolen over eight years via clipboard hijacking
- Unspent stolen crypto peaked in value at around $1.5 million in January 2025 as prices rose
- Over 15,000 infected machines were cut off from the botnet during a live operation in Las Vegas
CrowdStrike and U.S. federal law enforcement have taken down Sality, a botnet that ran for over two decades and spent its last eight years quietly stealing cryptocurrency from everyday users.
🚨DOJ JUST CUT DOWN A 20 YEAR BOTNET USED FOR CRYPTO THEFT!
The Justice Department said a U.S., Bulgaria, Hungary and Romania operation disrupted Sality, malware first seen in 2003 that later turned infected PCs into a peer-to-peer botnet used for crypto theft and other attacks.… pic.twitter.com/AdwK8cTLEj
— Crypto Banter (@crypto_banter) September 2, 2026
The attack worked by watching what users copied to their clipboard. When someone copied a Bitcoin or Ethereum wallet address to make a payment, the malware replaced it with an address controlled by the attackers. The victim would paste the address, hit send, and the funds would go to the wrong place with no warning.
How the Malware Worked
The tool behind the theft was called EggJagger. CrowdStrike described it as a clipjacking tool that sat silently on infected computers, monitoring clipboard activity.
Wallet addresses are long strings of characters. Almost no one types them by hand. That habit made users easy targets.
The malware spread through shared network drives and USB drives. It attached itself to programs and kept regenerating without any action needed from whoever ran it.
Sality had no central server, which made it harder to shut down. Infected machines talked directly to each other, checking in every 40 minutes to confirm their peers were still online.
How Authorities Took It Down
CrowdStrike found a weakness in that peer-to-peer structure. The company replaced real peer addresses with its own servers, cutting off more than 15,000 infected machines from the network.
The operation was carried out on Monday during a live demonstration at CrowdStrike’s Day Zero summit in Las Vegas.
The U.S. Justice Department announced the action on Tuesday. It was an international effort that included officials from Bulgaria, Hungary and Romania, along with private sector partners CrowdStrike and the Shadowserver Foundation.
The DOJ said the operation was based in Russia and that Sality had been installing malware on compromised devices since 2003.
Over eight years of clipboard hijacking, the attackers stole at least 12.1 million rubles, roughly $150,000 in cryptocurrency. A large portion of those stolen funds were never spent.
As crypto prices climbed, the value of those unspent holdings rose to around $1.5 million at their peak in January 2025.
The operation shows how a low-tech method, simply swapping a copied address, can run undetected for years.
Users can protect themselves by checking the first and last characters of a wallet address after pasting it, every time, before confirming a transaction.
CrowdStrike said the criminals behind Sality have now lost the ability to communicate with infected machines following the disruption.
Stop guessing and start investing with confidence. KnockoutStocks gives you the AI insights, market intelligence, and stock research you need to spot opportunities, cut through the noise, and make smarter investment decisions — all in one powerful platform.
Sign up today and get 50% OFF full access to our premium stock picks.
Simply use coupon code SPECIAL50 at checkout to claim your exclusive discount.







