CrowdStrike and the U.S. Division of Justice disrupted the Sality botnet, isolating greater than 15,000 contaminated machines that had been used to distribute malicious payloads. Lively since 2003, Sality spent the previous eight years primarily delivering EggJagger, a device that monitored copied cryptocurrency pockets addresses and changed them with addresses managed by its operator.
The operation focused a dangerous weak spot in cryptocurrency fee workflows. When malware adjustments an tackle earlier than a fee is accomplished, funds could be redirected to a distinct recipient. CrowdStrike estimates that EggJagger alone was accountable for a minimum of 12.1 million rubles, or roughly $150,000, in stolen cryptocurrency.
At present the @FBI, @TheJusticeDept, and the Protection Felony Investigative Service (DCIS) introduced a multinational operation with actions in america and Europe to disrupt the botnet often known as Sality.
Since 2003, the Sality botnet has put in malware on compromised… pic.twitter.com/HNIY3oCGYr
— FBI Cyber Division (@FBICyberDiv) September 1, 2026
Sality was first noticed in 2003 and developed right into a peer-to-peer botnet. Relatively than counting on a central command-and-control server, contaminated machines communicated instantly with each other. The malware additionally spreads by attaching itself to executable information shared via community shares, detachable drives, and file sharing.
In accordance with CrowdStrike, Sality’s technical position was to deploy extra payloads to contaminated machines. EggJagger turned its major payload over the previous eight years.
The clipjacking device monitored a sufferer’s clipboard for cryptocurrency pockets addresses and silently changed them with an tackle managed by the operator. An individual copying a Bitcoin or Ethereum tackle to make a fee may subsequently have funds redirected away from the meant recipient.
This mechanism differs from an change breach or a smart-contract exploit. It concerned the gadget and clipboard used within the means of getting ready a cryptocurrency fee, quite than an assault on the blockchain itself.
Commerce XRP on ByBit and Be part of 99Bitcoin’s Unique $1000 USDT Airdrop Marketing campaign
What the Takedown Proves, and What It Does Not
CrowdStrike’s Counter Adversary Operations group used Sality’s peer-to-peer design towards the botnet. The operation manipulated peer lists by eradicating reputable friends and inserting CrowdStrike-controlled sinkholes. This remoted contaminated machines from the operator’s management and prevented the botnet from receiving new tasking.
The U.S. Division of Justice, FBI, and Protection Felony Investigative Service took motion towards Sality-linked infrastructure in america. Regulation-enforcement companions in Bulgaria, Hungary, and Romania supported associated motion in Europe. The Shadowserver Basis is working with web suppliers to inform victims.
CrowdStrike tracks the operator as SALTY SPIDER. The agency stated the stolen cryptocurrency was largely left unspent, with the portfolio reaching a peak worth of about 147 million rubles in January 2025, nominally round $1.35 million.
Disrupting the operator’s management channel doesn’t take away malware from compromised methods. CrowdStrike stated that malware already current on contaminated machines stays energetic till it’s eliminated, which means affected methods nonetheless require remediation.
EXPLORE:Â Greatest Crypto Presales With Uneven Upside within the Present Market
Why the Theft Issues for Crypto Customers
The confirmed EggJagger theft complete is restricted to 1 payload household, however the mechanism exhibits how malware can intervene with a routine fee workflow. A copied tackle can originate from a reputable supply, whereas the clipboard content material is altered on an contaminated gadget earlier than a transaction is accomplished.
The greater than 15,000 machines remoted throughout the operation illustrate the dimensions of the infrastructure CrowdStrike addressed. The case facilities on clipboard substitution: malware monitored cryptocurrency pockets addresses and changed them with addresses managed by the operator, redirecting funds made out of contaminated computer systems.

Bitcoin and the Sality Disruption
Bitcoin’s market context and the Sality operation are separate points. The botnet used cryptocurrency addresses as a part of its theft scheme, however the proof surrounding the disruption doesn’t set up a connection between the operation and Bitcoin’s market path.
7d
30d
1y
All Time
The takedown is as a substitute a cybersecurity improvement involving the protection of fee workflows on compromised gadgets. Its fast impact, based on CrowdStrike, was to isolate contaminated machines in order that the operator may not talk with them or challenge new directions.
For cryptocurrency customers, the central challenge just isn’t a change to the underlying blockchain. It’s the threat that malware on a tool can alter fee info throughout a transaction workflow. The persevering with presence of malware on affected machines additionally means the disruption didn’t itself clear these methods.
MEXC
Go to MEXC
Observe 99Bitcoins on X For the Newest Market Updates and Subscribe on YouTube For Each day Knowledgeable Market Evaluation.
The submit Sality Takedown Isolates 15,000 Machines Utilized in Crypto Theft appeared first on 99Bitcoins.








