Multi-National Takedown of the Sality Botnet

The US Department of Justice announced on Tuesday that federal law enforcement, in coordination with cybersecurity firm CrowdStrike, had successfully disrupted the Sality botnet and its associated malware. The operation was carried out in an international collaboration involving Bulgarian, Hungarian, and Romanian authorities, along with private-sector partners CrowdStrike and the Shadowserver Foundation.

According to Justice Department officials, Sality had been installing malicious software on compromised devices as far back as 2003, leveraging the infrastructure to facilitate cryptocurrency theft and broader cyberattacks. As a direct result of the takedown, the operators behind Sality reportedly lost their ability to communicate with infected machines, effectively severing their control over the network.

The EggJagger Clipjacking Technique

CrowdStrike detailed the specific malware tool at the center of the operation, identifying it as EggJagger — a "clipjacking" utility designed to monitor a victim's clipboard for cryptocurrency wallet addresses. Once a user copied a Bitcoin or Ethereum address to initiate a payment, the tool would silently swap the destination with an address controlled by the attackers, redirecting the funds without the victim's knowledge.

The company reported that over the eight-year window preceding the disruption, the Sality operators used EggJagger to steal at least 12.1 million rubles, equivalent to roughly $150,000 in cryptocurrency. Notably, the total value of the "never-spent" stolen digital assets reached a peak of approximately $1.5 million in January 2025, suggesting that a significant portion of the ill-gotten gains remained unspent in the operators' wallets.

What This Means for Crypto Users

Beyond the direct financial losses, the Sality network also comprised approximately 15,000 infected computers organized into a peer-to-peer botnet. These machines were programmed to check in with the command infrastructure every 40 minutes to confirm they remained online, giving attackers a persistent foothold in vulnerable systems.

The operation underscores a growing threat vector for cryptocurrency holders: clipboard-based attacks that exploit the trust users place in their operating systems' copy-and-paste functionality. While the disruption of Sality removes one active threat, the underlying technique of wallet-address substitution remains a concern for anyone transacting in digital assets, particularly those working on unsecured or poorly maintained devices.