US Authorities and CrowdStrike Disrupt Sality Botnet, Stealing $150,000 in Crypto

iconTheCryptoBasic
Share
AI summary iconSummary
US authorities and CrowdStrike have taken down the Sality botnet, which stole over $150,000 in crypto since 2003. The network used the clipjacking tool EggJagger to swap victims' wallet addresses with the operator's, redirecting funds. Agencies in Bulgaria, Hungary, and Romania seized control of 15,000 infected machines in a peer-to-peer network. As liquidity and crypto markets remain under intense regulatory review, the takedown highlights ongoing efforts to secure digital assets. The disruption also comes as MiCA (EU Markets in Crypto-Assets Regulation) prepares to take effect, signaling tighter global oversight.

The US Justice Department said an international operation involving European law enforcement and private-sector partners disrupted Sality’s operations, cutting the malware network off from its operator. Sality had been linked to cryptocurrency theft and other cyberattacks.

The Justice Department said Tuesday that authorities in Bulgaria, Hungary and Romania participated in the effort alongside CrowdStrike and the Shadowserver Foundation. According to US officials, the malware network had been infecting devices and deploying malicious software since 2003.

EggJagger Redirected Crypto Payments

Over the previous eight years, Sality’s operator used a clipjacking tool known as EggJagger to steal at least 12.1 million rubles, equivalent to roughly $150,000 in cryptocurrency, according to CrowdStrike.

EggJagger monitored device clipboards for cryptocurrency wallet addresses and replaced them with addresses controlled by the operator. As a result, payments could be redirected when victims copied Bitcoin or Ethereum addresses before making transfers.

CrowdStrike said the value of stolen digital assets that remained unspent peaked at about 147 million rubles, or roughly $1.35 million, in January 2025.

Disruption Cuts Operator Off From Infected Computers

The operation severed the Sality operator’s ability to communicate with compromised machines, according to CrowdStrike.

More than 15,000 infected computers were part of Sality’s peer-to-peer botnet. The bots checked every 40 minutes whether known peers remained online, allowing machines within the decentralized network to communicate directly with one another.

CrowdStrike said the disruption isolated those infected machines from the operator, preventing them from receiving new payload instructions or direct payload transfers.

DisClamier: This content is informational and should not be considered financial advice. The views expressed in this article may include the author's personal opinions and do not reflect The Crypto Basic opinion. Readers are encouraged to do thorough research before making any investment decisions. The Crypto Basic is not responsible for any financial losses.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.