Global operation dismantles Sality botnet after crypto theft

CrowdStrike and law enforcement dismantled the Sality botnet, which stole over $150,000 in crypto by hijacking wallet addresses for eight years.

A multinational operation led by CrowdStrike, in collaboration with U.S. federal agencies and European law enforcement, has successfully dismantled the Sality botnet. This peer-to-peer malware network had been active since 2003 and, over the past eight years, specifically targeted cryptocurrency users. Sality deployed a clipboard hijacker known as EggJagger, which replaced copied Bitcoin and Ethereum wallet addresses with those controlled by the attackers. This method enabled the theft of at least 12.1 million rubles (approximately $150,000), while the value of untouched assets peaked at $1.35 million by early 2025. The botnet spread through peer-to-peer communication, LAN sharing, and USB drives, operating without a central server. CrowdStrike exploited vulnerabilities in Sality’s node identity verification, disconnecting over 15,000 infected devices through a protocol-level engineering operation. This takedown marks the end of a persistent threat to cryptocurrency users and neutralizes a network responsible for significant financial losses.

Related Tokens

Related News