Sality Botnet Dismantled After Years of Cryptocurrency Theft
- The Justice Department and CrowdStrike have disrupted the Sality botnet, active since 2003.
- For the past eight years, its main payload was EggJagger, which altered cryptocurrency wallet addresses on victims’ clipboards.
- CrowdStrike estimates at least $150,000 was stolen through EggJagger alone.
- The unspent cryptocurrency holdings peaked at about $1.35 million in January 2025.
- More than 15,000 machines worldwide were isolated by CrowdStrike’s operations team.
The Sality botnet operated without a central server, making it difficult to dismantle until now. Its architecture allowed infected machines to communicate directly and spread malware effectively over network shares and drives.
This operation marks a significant step in combating cybercrime related to Ethereum and other cryptocurrencies, as the botnet’s infrastructure has been taken down globally. (Source)