ChainCatcher report: On Tuesday, CrowdStrike and the U.S. Department of Justice announced the takedown of the Sality peer-to-peer botnet, which has been active since 2003. Over the past eight years, this botnet primarily hijacked cryptocurrency payments through the EggJagger malware, which monitored victims’ clipboard contents for cryptocurrency wallet addresses and replaced them with addresses controlled by the attackers, causing victims to send funds to strangers. CrowdStrike estimates that, through the EggJagger payload alone, the operators stole at least 12.1 million rubles (approximately $150,000). Most of the stolen cryptocurrency remains unspent; CrowdStrike assessed that these idle assets were worth approximately 147 million rubles (roughly $1.35 million) at their peak in January 2025. Sality has persisted this long because it lacks a central server that can be seized—infected machines communicate directly with one another. This multinational operation involved the United States, Bulgaria, Hungary, and Romania. The U.S. Department of Justice, FBI, and Defense Criminal Investigative Service seized Sality-related domains within the United States, while law enforcement agencies across multiple European countries seized additional domains. CrowdStrike exploited architectural vulnerabilities to isolate over 15,000 infected machines into honey pots under its control. The operators have been traced to SALTY SPIDER, who previously launched a denial-of-service attack against the Russian cryptocurrency exchange AvanChange in September 2023.
US DOJ and CrowdStrike Take Down Sality Botnet, Stealing Over 12 Million Rubles in Crypto
ChaincatcherShare
The U.S. Department of Justice and CrowdStrike announced the takedown of the Sality botnet, active since 2003. The botnet used EggJagger malware to hijack cryptocurrency news payments by swapping wallet addresses. CrowdStrike estimates the attackers stole at least 12.1 million rubles using this method. Unclaimed assets reached 147 million rubles in January 2025. A joint operation involving the U.S., Bulgaria, Hungary, and Romania resulted in the seizure of related domains and infected devices. The operators, known as SALTY SPIDER, recently targeted the Russian exchange AvanChange. The decentralized nature of Sality made it resilient, but its infrastructure has now been isolated. The operation underscores the effectiveness of coordinated enforcement in upholding cryptocurrency regulations.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.



