US and EU Take Down Sality Botnet Stealing Ethereum and Bitcoin

icon币界网
Share
AI summary iconSummary
On September 1, the U.S. Department of Justice and CrowdStrike, with support from EU and Balkan law enforcement, dismantled the Sality botnet, targeting its role in stealing Ethereum and Bitcoin. Active since 2003, the botnet used the EggJagger payload to replace wallet addresses in clipboard transactions, siphoning funds over eight years. More than 15,000 infected devices were isolated globally, and domains were seized in the U.S. and EU. The takedown aligns with MiCA (EU Markets in Crypto-Assets Regulation) efforts to strengthen crypto markets. CrowdStrike estimates EggJagger generated at least $150,000 for attackers, with stolen assets peaking at $135,000 in January 2025.
CoinDesk reports:

On September 1, the U.S. Department of Justice, in collaboration with cybersecurity firm CrowdStrike, announced the takedown of the long-active Sality botnet, in coordination with law enforcement agencies in Bulgaria, Hungary, and Romania. The botnet, active since 2003, primarily stole Bitcoin and Ethereum over the past eight years by tampering with cryptocurrency wallet addresses on victims' computers.

For the past eight years, it has primarily been used to replace wallet addresses.

CrowdStrike stated that Sality's primary payload in recent years is a malicious program called EggJagger. When users copy a wallet address to prepare a transfer, the program replaces the address in the clipboard with one controlled by the attacker, resulting in funds being stolen.

The company estimates that EggJagger alone generated at least 12.1 million rubles in revenue for operators, equivalent to approximately $150,000. Prior to this, Sality was also used to steal account credentials, send spam, provide proxy services, and launch denial-of-service attacks.

Open interest once rose to $1.35 million.

CrowdStrike stated that most of the stolen crypto assets were not sold immediately. As cryptocurrency prices rose, the value of these untouched holdings reached approximately 147 million rubles, or about $1.35 million, in January 2025.

This means the attacker achieved a higher paper gain than the initial theft amount by holding the stolen assets over the long term. The report also noted that, based on purchasing power in major Western cities, the peak value of these assets was approximately $4 million.

Simultaneous seizure of related infrastructure across multiple countries

A key reason Sality has persisted for years is that it has no single central server. Infected devices communicate directly with each other, and the malware attaches itself to executable files, continuing to spread through network shares and removable storage devices.

However, this peer-to-peer structure also became a vulnerability exploited by law enforcement and security teams. CrowdStrike noted that Sality nodes rarely verify the identity of newly joining devices. Leveraging this, their team removed legitimate nodes from the infected devices’ address lists and replaced them with addresses of sinkhole servers under their control, ultimately isolating over 15,000 machines worldwide.

The U.S. Department of Justice, FBI, and Defense Criminal Investigative Service have seized domains associated with Sality in the United States, while police in Bulgaria, Hungary, and Romania have taken down operations in Europe. The Shadowserver Foundation is working with internet service providers to notify victims.

Additional information: CrowdStrike also noted that the actor codenamed SALTY SPIDER used this network attack to target the Russian cryptocurrency exchange AvanChange in September 2023. While some infected devices have been redirected to sinkhole servers controlled by CrowdStrike, the malicious software on the machines still requires manual removal by users.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.