U.S., CrowdStrike Disrupt Sality Botnet Used to Steal Crypto
Federal authorities and CrowdStrike, with partners in Bulgaria, Hungary and Romania, disrupted the Sality botnet that enabled about $150,000 in crypto theft.
On Tuesday the Justice Department announced that federal law enforcement, working with cybersecurity firm CrowdStrike and international partners, disrupted the Sality botnet and related malware used to steal cryptocurrency. The operation included cooperation with authorities in Bulgaria, Hungary and Romania and technical support from the Shadowserver Foundation.
The department said Sality had been installing malware on compromised devices since 2003 and used those infections for cryptocurrency theft and other cyberattacks. CrowdStrike identified a tool the operators used, called EggJagger, a clipjacking program that monitors a user’s clipboard for cryptocurrency wallet addresses and replaces them with addresses controlled by the attackers.
CrowdStrike explained: “When a victim copies a Bitcoin or Ethereum address to make a payment, the funds are redirected.”
CrowdStrike’s analysis found the actors behind Sality used EggJagger over the past eight years to steal at least 12.1 million rubles, roughly $150,000. The firm also reported that some digital assets tied to the operation were never spent and that their combined value peaked near $1.5 million in January 2025. The Justice Department and partners targeted those assets and the infrastructure supporting the thefts in the disruption.
Sality operated as a peer-to-peer botnet of about 15,000 infected computers. Infected devices checked in with the botnet every 40 minutes, allowing operators to push updates and maintain control. After the disruption, the operators lost the ability to communicate with many of those machines, according to authorities and CrowdStrike.
The Justice Department did not provide details about arrests or asset seizures in its announcement. The Shadowserver Foundation assisted by identifying affected systems and coordinating remediation with network owners.
First detected in the early 2000s, Sality has been linked to multiple campaigns that distributed other payloads and enabled remote control of infected PCs. Security researchers have previously noted that clipboard hijacking tools are a common method for stealing cryptocurrencies because they replace legitimate wallet addresses at the moment of payment.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.








