The U.S. Department of Justice and cybersecurity firm CrowdStrike have disrupted Sality, a peer-to-peer botnet that has been active since 2003 and spent the past eight years stealing cryptocurrency by tampering with wallet addresses on infected computers.
According to CrowdStrike, the operation seized Sality-linked domains in the United States and removed parts of the botnet’s infrastructure in Bulgaria, Hungary, and Romania. More than 15,000 infected devices were cut off from the operators and redirected to sinkholes controlled by CrowdStrike.
How the theft worked
The botnet’s main payload in this campaign was malware known as EggJagger. CrowdStrike said it monitored victims’ clipboards for cryptocurrency wallet addresses and then replaced the copied address with one controlled by the attackers.
That method allowed the operators to divert payments without needing to break into an exchange account or directly access a user’s wallet. If a victim pasted the altered address into a transfer, the funds would be sent to the attackers instead of the intended recipient.
Losses tied to EggJagger
CrowdStrike estimates that at least $150,000 was stolen through EggJagger. The company also said the value of unspent holdings linked to the operation climbed much higher at one point, potentially reaching about $1.35 million, or roughly 147 million rubles, in January 2025.
The report said the stolen cryptocurrency was largely left untouched. CrowdStrike described that approach as more profitable than some of the botnet’s other activities, suggesting the operators benefited from holding the assets rather than quickly moving or cashing them out.
What the takedown changed
The disruption targeted key parts of Sality’s infrastructure. U.S.-linked domains tied to the botnet were seized, while additional components were taken down across Bulgaria, Hungary, and Romania as part of the broader action.
As a result, infected machines no longer communicate with the botnet’s operators. Instead, they now check in with CrowdStrike-run sinkholes, a common defensive measure that isolates compromised devices and prevents them from receiving further instructions.
Next steps for victims and defenders
CrowdStrike said it has published detection rules and indicators to help organizations identify infections and investigate possible exposure. That gives network defenders a way to find systems that may still be compromised even though the command infrastructure has been disrupted.
The confirmed next step is remediation on affected machines. While the sinkholing operation has cut operator access to more than 15,000 devices, those systems still need to be identified and cleaned by their owners to fully remove the malware and reduce the risk of future abuse.
Source: decrypt.co