Sality Botnet Dismantled After Eight Years of Stealing Bitcoin and Ethereum
CrowdStrike and the U.S. Justice Department disrupted Sality, a botnet active since 2003 that spread through infected files on networks and removable drives. For the past eight years, its main payload was EggJagger, a clipboard-hijacking tool that swapped copied cryptocurrency wallet addresses to steal Bitcoin and Ethereum payments. CrowdStrike says EggJagger likely stole at least 12.1 million rubles, and the untouched stolen crypto may have been worth about 147 million rubles at its peak. Sality persisted because it had no central server; infected machines connected directly to each other. CrowdStrike used that architecture to insert sinkholes and isolate more than 15,000 machines worldwide. U.S. and European authorities seized related domains, and victims are being notified. The operator, tracked as SALTY SPIDER, also occasionally used the botnet for attacks, including a 2023 denial-of-service hit on a crypto exchange.
