Bitcoin

Bitcoin

$77,213.55

BTC 0.28%

Ethereum

Ethereum

$2,106.63

ETH 0.42%

  • Login
  • Register
Metaverse Media Group
  • Home
  • Crypto
  • NFTs
  • Artificial Intelligence
  • More
    • Technology
    • Business
    • Newsletter
No Result
View All Result
  • Home
  • Crypto
  • NFTs
  • Artificial Intelligence
  • More
    • Technology
    • Business
    • Newsletter
No Result
View All Result
Metaverse Media Group

Sality Botnet Dismantled After Eight Years of Stealing Bitcoin and Ethereum

Sality Botnet Dismantled After Eight Years of Stealing Bitcoin and Ethereum

Decryptby Decrypt
2 September 2026
In brief The Justice Department and CrowdStrike said Tuesday they had disrupted Sality, a peer-to-peer botnet running since 2003. Its primary payload for the past eight years was EggJagger, which replaced cryptocurrency wallet addresses copied to a victim’s clipboard. CrowdStrike estimates the operator stole at least $150,000 through that payload alone, and that the unspent holdings later peaked far higher….

In brief

  • The Justice Department and CrowdStrike said Tuesday they had disrupted Sality, a peer-to-peer botnet running since 2003.
  • Its primary payload for the past eight years was EggJagger, which replaced cryptocurrency wallet addresses copied to a victim’s clipboard.
  • CrowdStrike estimates the operator stole at least $150,000 through that payload alone, and that the unspent holdings later peaked far higher.

CrowdStrike and the Justice Department have dismantled Sality, a botnet that has circulated since 2003 and spent its last eight years hijacking cryptocurrency payments by rewriting wallet addresses on infected computers, the security firm said Tuesday.

Sality itself did little beyond delivering other people’s payloads. For eight years its primary cargo was EggJagger, which CrowdStrike calls “a clipjacking tool that monitors the clipboard for cryptocurrency wallet addresses” and swaps them for the operator’s own. A victim copying a Bitcoin or Ethereum address to pay someone sends the money to a stranger.

A multinational operation to disrupt the botnet and malware known as Sality and take down its infrastructure was announced today, involving actions in the United States, #Bulgaria, #Hungary, and #Romania, in collaboration with private industry partners CrowdStrike and the… pic.twitter.com/w34Bal8LG7

— FBI Los Angeles (@FBILosAngeles) September 1, 2026

CrowdStrike puts the take at a minimum of 12.1 million rubles, roughly $150,000, from EggJagger alone. Before EggJagger, the botnet earned its keep delivering credential theft, spam, proxy services and denial-of-service payloads.

What the operator never spent

The stolen coins were largely left untouched, which turned out to be the more profitable decision. CrowdStrike values the never-spent portfolio at a peak of about 147 million rubles in January 2025, a nominal $1.35 million, or roughly the purchasing power of $4 million in a Western capital.

Sality survived since 2003 because it had no central server to seize. Infected machines talked directly to one another, and the malware spread by attaching itself to executable files passed over network shares and removable drives, regenerating without effort from its operator.

Myriad: Bitcoin price next move? Click to make your prediction.
Myriad: Bitcoin price next move? Click to make your prediction.

That architecture was also the way in. Bots accepted any reachable machine that answered the handshake correctly, with no check on who was joining. CrowdStrike’s Counter Adversary Operations team used that access to strip legitimate peers from each bot’s address list and insert its own sinkholes, isolating more than 15,000 machines worldwide.

The Justice Department, FBI and Defense Criminal Investigative Service seized Sality-linked domains in the U.S., while police in Bulgaria, Hungary and Romania took down others in Europe. The Shadowserver Foundation is working with internet providers to notify victims.

The operator, whom CrowdStrike tracks as SALTY SPIDER, occasionally turned the botnet on targets of their own. A denial-of-service payload in September 2023 hit AvanChange, a Russian cryptocurrency exchange, and was compiled seconds before upload, which CrowdStrike reads as an impulsive response to a personal grievance. The firm believes the operator used exchanges like it to convert stolen coins into cash.

Infected machines now report to CrowdStrike-controlled sinkholes rather than their owner. The company has published detection rules and network indicators, and warns that malware already sitting on those machines stays active until someone removes it.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

Read the full article on Decrypt.co
in Crypto
Reading Time: 6 mins read
0
0
22
VIEWS
Share on TwitterShare on Facebook

Subscribe to our newsletter

For the latest news & monthly prize giveaways
Join Now

Subscribe to our newsletter

For the latest news & monthly prize giveaways
Join Now
ADVERTISEMENT

Related Posts

Don’t Fall for BTC-Stealing Fake Claude Apps as Fable 5.1 and Mythos 5.1 Released
Crypto

Don’t Fall for BTC-Stealing Fake Claude Apps as Fable 5.1 and Mythos 5.1 Released

49 minutes ago
22
World Adds Post-Quantum Security to New ZK Proving Toolkit
Crypto

World Adds Post-Quantum Security to New ZK Proving Toolkit

3 hours ago
23
G20 Backs Clear Regulatory Pathways for Digital Asset Growth
Crypto

G20 Backs Clear Regulatory Pathways for Digital Asset Growth

5 hours ago
22

Comments

Please login to join discussion
ADVERTISEMENT

Latest News

  • All
  • Crypto
  • NFTs
  • Technology
  • Business
Don’t Fall for BTC-Stealing Fake Claude Apps as Fable 5.1 and Mythos 5.1 Released
Crypto

Don’t Fall for BTC-Stealing Fake Claude Apps as Fable 5.1 and Mythos 5.1 Released

Bitcoin.com News
by Bitcoin.com News
49 minutes ago
22
London’s first self-driving taxis for hire hit the streets
Technology

London’s first self-driving taxis for hire hit the streets

The Guardian
by The Guardian
2 hours ago
23
World Adds Post-Quantum Security to New ZK Proving Toolkit
Crypto

World Adds Post-Quantum Security to New ZK Proving Toolkit

Bitcoin.com News
by Bitcoin.com News
3 hours ago
23
G20 Backs Clear Regulatory Pathways for Digital Asset Growth
Crypto

G20 Backs Clear Regulatory Pathways for Digital Asset Growth

Bitcoin.com News
by Bitcoin.com News
5 hours ago
22
Meta Pushes Its New AI Agent on Employees—but Eases Off on Tokenmaxxing
AI

Meta Pushes Its New AI Agent on Employees—but Eases Off on Tokenmaxxing

Wired
by Wired
6 hours ago
22
Fidelity Warns Bitcoin’s Private Keys Face Future Quantum Risk
Crypto

Fidelity Warns Bitcoin’s Private Keys Face Future Quantum Risk

Bitcoin.com News
by Bitcoin.com News
6 hours ago
22
Load More
Next Post
Morning Minute: Bitcoin Enters ‘Rektember’ After Best August Since 2017

Morning Minute: Bitcoin Enters ‘Rektember’ After Best August Since 2017

ADVERTISEMENT

Follow Us

Categories

  • Crypto
  • NFTs
  • AI
  • Technology
  • Business
  • Crypto
  • NFTs
  • AI
  • Technology
  • Business
Subscribe to our Newsletter

© 2022 Metaverse Media Group – The Metaverse Mecca

Privacy and Cookie Policy | Sitemap

Welcome Back!

Sign In with Google
OR

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Sign Up with Google
OR

Fill the forms below to register

*By registering into our website, you agree to the Terms & Conditions and Privacy Policy.
All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Crypto
  • NFTs
  • Artificial Intelligence
  • More
    • Technology
    • Business
    • Newsletter
Bitcoin

Bitcoin

$77,213.55

BTC 0.28%

Ethereum

Ethereum

$2,106.63

ETH 0.42%

  • Login
  • Sign Up
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.

Subscribe to our newsletter

Get the latest news & win monthly prizes

Subscribe to our newsletter

For the Latest News and Monthly Prize Giveaways

Join Now
Join Now