Huo Xing Finance reports that CrowdStrike and the U.S. Department of Justice announced on Tuesday the takedown of the Sality peer-to-peer botnet, which has been active since 2003. Over the past eight years, this botnet primarily hijacked cryptocurrency payments through the EggJagger malware, which monitored victims’ clipboard contents for cryptocurrency wallet addresses and replaced them with addresses controlled by the attackers, causing victims to send funds to strangers. CrowdStrike estimates that, through the EggJagger payload alone, the operators stole at least 12.1 million rubles (approximately $150,000). Most of the stolen cryptocurrency remains unspent; CrowdStrike assessed that these unused assets were worth approximately 147 million rubles (roughly $1.35 million) at their peak in January 2025. Sality has persisted this long because it lacks a central server that can be seized—infected machines communicate directly with each other. This multinational operation involved the United States, Bulgaria, Hungary, and Romania. The U.S. Department of Justice, FBI, and Defense Criminal Investigative Service seized Sality-related domains within the United States, while law enforcement agencies in multiple European countries seized additional domains. CrowdStrike exploited architectural vulnerabilities to isolate over 15,000 infected machines into honeypots under its control. The operators have been traced to SALTY SPIDER, who previously launched a denial-of-service attack against the Russian cryptocurrency exchange AvanChange in September 2023.
US DOJ and CrowdStrike Take Down Sality Botnet, Stealing Over $150,000 in Crypto
MarsBitShare
The U.S. Department of Justice and CrowdStrike dismantled the Sality botnet, active since 2003. The group used the EggJagger malware to steal cryptocurrency by swapping wallet addresses in victims’ clipboards. Over $150,000 in cryptocurrency was siphoned, with stolen funds peaking at $1.35 million in January 2025. The operation spanned the U.S., Bulgaria, Hungary, and Romania. Law enforcement seized domains, and CrowdStrike identified the operators as SALTY SPIDER, who also launched a DDoS attack on a Russian exchange in 2023. The group infected over 15,000 machines using honeypots. The takedown underscores the importance of cryptocurrency regulations and global cooperation in combating cybercrime.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.



