Sality Botnet Dismantled After Eight Years of Stealing Bitcoin and Ethereum

CrowdStrike and the DOJ isolated more than 15,000 infected machines in a malware takedown spanning four countries.

By Decrypt Agent

3 min read

CrowdStrike and the Justice Department have dismantled Sality, a botnet that has circulated since 2003 and spent its last eight years hijacking cryptocurrency payments by rewriting wallet addresses on infected computers, the security firm said Tuesday.

Sality itself did little beyond delivering other people's payloads. For eight years its primary cargo was EggJagger, which CrowdStrike calls "a clipjacking tool that monitors the clipboard for cryptocurrency wallet addresses" and swaps them for the operator's own. A victim copying a Bitcoin or Ethereum address to pay someone sends the money to a stranger.

CrowdStrike puts the take at a minimum of 12.1 million rubles, roughly $150,000, from EggJagger alone. Before EggJagger, the botnet earned its keep delivering credential theft, spam, proxy services and denial-of-service payloads.

What the operator never spent

The stolen coins were largely left untouched, which turned out to be the more profitable decision. CrowdStrike values the never-spent portfolio at a peak of about 147 million rubles in January 2025, a nominal $1.35 million, or roughly the purchasing power of $4 million in a Western capital.

Sality survived since 2003 because it had no central server to seize. Infected machines talked directly to one another, and the malware spread by attaching itself to executable files passed over network shares and removable drives, regenerating without effort from its operator.

Myriad: Bitcoin price next move? Click to make your prediction.

That architecture was also the way in. Bots accepted any reachable machine that answered the handshake correctly, with no check on who was joining. CrowdStrike's Counter Adversary Operations team used that access to strip legitimate peers from each bot's address list and insert its own sinkholes, isolating more than 15,000 machines worldwide.

The Justice Department, FBI and Defense Criminal Investigative Service seized Sality-linked domains in the U.S., while police in Bulgaria, Hungary and Romania took down others in Europe. The Shadowserver Foundation is working with internet providers to notify victims.

The operator, whom CrowdStrike tracks as SALTY SPIDER, occasionally turned the botnet on targets of their own. A denial-of-service payload in September 2023 hit AvanChange, a Russian cryptocurrency exchange, and was compiled seconds before upload, which CrowdStrike reads as an impulsive response to a personal grievance. The firm believes the operator used exchanges like it to convert stolen coins into cash.

Infected machines now report to CrowdStrike-controlled sinkholes rather than their owner. The company has published detection rules and network indicators, and warns that malware already sitting on those machines stays active until someone removes it.

Get crypto news straight to your inbox--

sign up for the Decrypt Daily below. (It’s free).

Recommended News