AltcoinBuzzAltcoinBuzz
Subscribe
  • Crypto News
  • Crypto Research
  • Technical Analysis
AltcoinBuzzAltcoinBuzz

An independent digital media outlet delivering crypto research, news, and technical analysis to a community of 600,000+ users.

Follow us on:

Discover

  • Crypto Research
  • Crypto News
  • Technical Analysis
  • Key Opinions
  • Upcoming Launches

Categories

  • Bitcoin BTC
  • RWA
  • Technology
  • Altcoins
  • Regulation

Company

  • Affiliates
  • Partners & Sponsors
  • Careers
  • Contact
  • Terms of Use
  • Subscription Terms
  • About the ALTCOIN BUZZ
  • Privacy Policy
  • Contact ALTCOIN BUZZ
  • Advertise with us

Copyright 2026 ALTCOIN BUZZ. All rights reserved.Something is buzzzzzzzing.
HomeCrypto NewsSality Botnet Dismantled After Eight Years of Stealing Bitcoin and Ethereum
Crypto NewsRegulationTechnology

Sality Botnet Dismantled After Eight Years of Stealing Bitcoin and Ethereum

The Sality botnet has been dismantled after eight years of stealing cryptocurrency through EggJagger, with more than 15,000 infected machines isolated worldwide.

AAnmol Billa•Sep 3, 2026
Sality botnet dismantled after stealing Bitcoin and Ethereum through malware
MentionedBTC$79,066.00+2.39%ETH$2,440.89+1.59%

The Sality botnet, a malware network active since 2003, has been dismantled after spending its final eight years targeting cryptocurrency payments, according to CrowdStrike.

CrowdStrike and the U.S. Department of Justice isolated more than 15,000 infected machines across multiple countries after disrupting the botnet's peer-to-peer infrastructure.

The operation targeted Sality's cryptocurrency-stealing payload, EggJagger, which monitored victims' clipboards and replaced copied Bitcoin and Ethereum wallet addresses with addresses controlled by the attackers.

How Sality Stole Bitcoin and Ethereum

Sality primarily acted as a delivery network for other malware. During its final eight years, one of its main payloads was EggJagger, a crypto clipjacking tool designed to intercept cryptocurrency wallet addresses.

When a victim copied a Bitcoin or Ethereum address to make a payment, EggJagger could replace it with the attacker's address.

The victim would then unknowingly send their cryptocurrency to the wrong wallet.

CrowdStrike estimates EggJagger generated at least 12.1 million rubles, roughly $150,000, in stolen cryptocurrency.

Before targeting crypto payments, Sality was used to distribute credential-stealing malware, spam tools, proxy services and denial-of-service payloads.

$1.35M in Crypto Was Left Untouched

One of the most unusual aspects of the Sality operation was what happened to the stolen cryptocurrency.

Much of the crypto was apparently never spent.

CrowdStrike estimates the stolen portfolio reached approximately 147 million rubles in January 2025, equivalent to around $1.35 million at the time.

The untouched funds helped investigators understand the scale of the operation and track the cryptocurrency connected to the malware.

Why Sality Was So Difficult to Dismantle

Sality survived for more than two decades partly because it did not depend on a traditional centralized command server.

Instead, infected computers communicated directly with one another through a peer-to-peer network.

The malware could also spread by attaching itself to executable files transferred through network shares and removable drives.

That decentralized structure made it difficult for authorities to simply seize a server and shut down the operation.

CrowdStrike's Counter Adversary Operations team instead infiltrated the botnet's communication system. It removed legitimate peers from infected machines' address lists and inserted sinkholes controlled by the security firm.

More than 15,000 infected machines worldwide were subsequently isolated from the botnet's operators.

FBI and European Authorities Seize Infrastructure

The disruption involved authorities across several countries.

The U.S. Department of Justice, FBI and Defense Criminal Investigative Service seized Sality-linked domains in the United States.

Police authorities in Bulgaria, Hungary and Romania also took action against Sality infrastructure in Europe.

The Shadowserver Foundation is working with internet service providers to notify affected users.

The operation represents a coordinated effort to disrupt both the botnet's infrastructure and its ability to communicate with infected computers.

Sality Operator Also Targeted a Crypto Exchange

CrowdStrike tracks the suspected operator behind the activity as SALTY SPIDER.

The group did more than steal cryptocurrency through clipboard manipulation. In September 2023, a Sality-linked denial-of-service payload targeted AvanChange, a Russian cryptocurrency exchange.

CrowdStrike said the payload was compiled only seconds before it was uploaded, suggesting the attack may have been an impulsive response to a personal grievance.

The security firm also believes cryptocurrency exchanges may have been used to convert stolen assets into cash.

Infected Computers Are Still at Risk

The Sality takedown does not automatically remove the malware from affected computers.

The infected machines now communicate with CrowdStrike-controlled sinkholes rather than the botnet's operator, but the underlying malware can remain active.

CrowdStrike has published detection rules and network indicators to help identify infections.

Users whose systems were compromised therefore still need to remove the malware rather than assuming the takedown has cleaned their machines.

Sality Takedown Highlights Crypto Malware Risks

The Sality operation shows how established malware networks can adapt to cryptocurrency.

Instead of directly attacking a crypto exchange or blockchain, EggJagger targeted one of the simplest points in the payment process: the clipboard.

A single address replacement could redirect a Bitcoin or Ethereum payment without changing the blockchain itself.

The takedown also demonstrates why decentralized malware networks can remain difficult to eliminate years after their initial deployment.

Sality may now be isolated, but infected machines remain at risk until the malware itself is removed.

The information discussed by Altcoin Buzz is not financial advice. This is for educational, entertainment, and informational purposes only. Any information or strategies are thoughts and opinions relevant to the accepted levels of risk tolerance of the writer/reviewers and their risk tolerance may be different than yours. We are not responsible for any losses that you may incur as a result of any investments directly or indirectly related to the information provided. Bitcoin and other cryptocurrencies are high-risk investments so please do your due diligence.

Copyright Altcoin Buzz Pte Ltd.

Related

Bitcoin ETF inflows rise as Ethereum XRP and Solana ETFs record outflows
Altcoins
Sep 3, 2026

Solana, XRP and Ethereum ETFs Turn Red as Bitcoin Funds Add $101M

Bitcoin ETFs attracted $101.15 million on September 2 as Ethereum, XRP and Solana funds recorded daily outflows, highlighting a shift toward BTC.

SOLXRP+1 more
Anmol Billa
Bitcoin recovers toward $78K as PONS and Arbitrum rally
Bitcoin BTCAltcoins
Sep 3, 2026

Bitcoin Rebounds Above $78K as PONS Surges 300% and ARB Extends Rally

Bitcoin price recovered toward $78,000 as a weaker dollar supported risk assets, while PONS and Arbitrum extended their Robinhood Chain-fueled rallies.

BTC PONS+1 more
Bikash Deka
Ether and XRP ETF outflows as Bitcoin ETF inflows rebound
Altcoins
Sep 3, 2026

Ether, XRP ETF Inflow Streaks End as Bitcoin Funds Rebound

Ether and XRP ETFs ended their long inflow streaks on Wednesday, while Bitcoin ETFs attracted $101.2 million as crypto prices came under pressure.

XRP
Saloni Rathi
FBI Los Angeles
FBI Los Angeles
FBI
@FBILosAngeles
·Follow

A multinational operation to disrupt the botnet and malware known as Sality and take down its infrastructure was announced today, involving actions in the United States, #Bulgaria, #Hungary, and #Romania, in collaboration with private industry partners CrowdStrike and the Show more

Image
11:30 PM · Sep 1, 2026
146
Reply
Read 7 replies