Skip to content

Bitcoin Ethereum Botnet Dismantled After 8 Years

Sality Botnet Dismantled After Years of Cryptocurrency Theft

  • The Justice Department and CrowdStrike have disrupted the Sality botnet, active since 2003.
  • For the past eight years, its main payload was EggJagger, which altered cryptocurrency wallet addresses on victims’ clipboards.
  • CrowdStrike estimates at least $150,000 was stolen through EggJagger alone.
  • The unspent cryptocurrency holdings peaked at about $1.35 million in January 2025.
  • More than 15,000 machines worldwide were isolated by CrowdStrike’s operations team.

The Sality botnet operated without a central server, making it difficult to dismantle until now. Its architecture allowed infected machines to communicate directly and spread malware effectively over network shares and drives.

This operation marks a significant step in combating cybercrime related to Ethereum and other cryptocurrencies, as the botnet’s infrastructure has been taken down globally. (Source)

Share