On September 1, the U.S. Department of Justice, in collaboration with cybersecurity firm CrowdStrike, announced the takedown of the long-active Sality botnet, in coordination with law enforcement agencies in Bulgaria, Hungary, and Romania. The botnet, active since 2003, primarily stole Bitcoin and Ethereum over the past eight years by tampering with cryptocurrency wallet addresses on victims' computers.
For the past eight years, it has primarily been used to replace wallet addresses.
CrowdStrike stated that Sality's primary payload in recent years is a malicious program called EggJagger. When users copy a wallet address to prepare a transfer, the program replaces the address in the clipboard with one controlled by the attacker, resulting in funds being stolen.
The company estimates that EggJagger alone generated at least 12.1 million rubles in revenue for operators, equivalent to approximately $150,000. Prior to this, Sality was also used to steal account credentials, send spam, provide proxy services, and launch denial-of-service attacks.
Open interest once rose to $1.35 million.
CrowdStrike stated that most of the stolen crypto assets were not sold immediately. As cryptocurrency prices rose, the value of these untouched holdings reached approximately 147 million rubles, or about $1.35 million, in January 2025.
This means the attacker achieved a higher paper gain than the initial theft amount by holding the stolen assets over the long term. The report also noted that, based on purchasing power in major Western cities, the peak value of these assets was approximately $4 million.
Simultaneous seizure of related infrastructure across multiple countries
A key reason Sality has persisted for years is that it has no single central server. Infected devices communicate directly with each other, and the malware attaches itself to executable files, continuing to spread through network shares and removable storage devices.
However, this peer-to-peer structure also became a vulnerability exploited by law enforcement and security teams. CrowdStrike noted that Sality nodes rarely verify the identity of newly joining devices. Leveraging this, their team removed legitimate nodes from the infected devices’ address lists and replaced them with addresses of sinkhole servers under their control, ultimately isolating over 15,000 machines worldwide.
The U.S. Department of Justice, FBI, and Defense Criminal Investigative Service have seized domains associated with Sality in the United States, while police in Bulgaria, Hungary, and Romania have taken down operations in Europe. The Shadowserver Foundation is working with internet service providers to notify victims.
Additional information: CrowdStrike also noted that the actor codenamed SALTY SPIDER used this network attack to target the Russian cryptocurrency exchange AvanChange in September 2023. While some infected devices have been redirected to sinkhole servers controlled by CrowdStrike, the malicious software on the machines still requires manual removal by users.


