The United States Justice Department and cybersecurity firm CrowdStrike announced that they have successfully dismantled Sality, a peer-to-peer botnet operating since 2003. The botnet, which infected computers globally, used a decentralized architecture to avoid shutdown and has been responsible for significant cryptocurrency thefts in recent years.
Longstanding Threat to Cryptocurrency Users
For the past eight years, Sality’s main function was to deliver EggJagger, a malicious payload that targets cryptocurrency owners. EggJagger works by monitoring the clipboard of infected machines and replacing any copied cryptocurrency wallet address with one under the attacker’s control. As a result, unsuspecting users would send funds to the operator instead of their intended recipient.
EggJagger consistently intercepted cryptocurrency addresses, rerouting payments made in Bitcoin or Ethereum to wallets belonging to the attacker.
CrowdStrike, a leading provider of cybersecurity solutions, estimates that EggJagger alone enabled the theft of at least 12.1 million rubles, or approximately $150,000, from victims. The majority of these stolen funds remained untouched after the theft, which allowed their value to appreciate as cryptocurrency prices climbed. At their peak in January 2025, the unspent assets had grown to 147 million rubles, equivalent to a nominal $1.35 million and roughly $4 million in purchasing power for some currencies.
| Metric | Value | Date |
|---|---|---|
| Minimum theft from EggJagger | $150,000 | 2018–2026 |
| Peak unspent stolen holdings | $1.35 million (nominal) | January 2025 |
| Estimated purchasing power | $4 million (approx.) | January 2025 |
Before its use as a cryptocurrency-targeted attack, Sality acted as a carrier for a range of malicious tools including credential theft, spam, proxy services and denial-of-service payloads.
International Operation Targets Botnet Infrastructure
Authorities from the United States, Bulgaria, Hungary, and Romania collaborated alongside private sector partners such as CrowdStrike to disrupt Sality’s operations. The FBI Los Angeles Field Office and the Defense Criminal Investigative Service seized crucial domains linked to Sality in the US, while European authorities targeted infrastructure in their respective countries.
The Shadowserver Foundation, a non-profit organization specializing in cybersecurity, has partnered with internet service providers to notify victims and help remediate infected machines.
Sality persisted for over two decades because it did not rely on a central command server. Instead, each infected computer directly connected to others, enabling the malware to spread through executable files traversing network shares and removable drives. The protocol accepted any machine that successfully responded to its handshake protocol, without any robust authentication.
CrowdStrike’s Counter Adversary Operations team exploited this weakness to reconfigure the botnet. By inserting their own nodes and removing legitimate peers from each infected machine’s address list, they successfully isolated over 15,000 infected systems worldwide.
The Sality operator, tracked by CrowdStrike under the name SALTY SPIDER, occasionally deployed the botnet for targeted attacks. In September 2023, the botnet was used for a denial-of-service action against AvanChange, a Russian cryptocurrency exchange, supposedly as retaliation for personal reasons. CrowdStrike believes exchanges like AvanChange were also channels to convert stolen digital assets into cash.
Currently, affected computers now communicate with so-called “sinkholes” managed by CrowdStrike, disrupting the operator’s control. CrowdStrike has provided detection guidelines and network indicators for the public and emphasized that infected systems will remain at risk until the malware is manually removed.
Rise of Adaptive AI-Powered Malware
Experts warn that recent advances in artificial intelligence could fuel the next wave of cyber threats. New research from the University of Toronto, Vector Institute, University of Cambridge, and ServiceNow demonstrates a proof-of-concept AI worm capable of scanning for vulnerabilities, developing tailored attack strategies, and autonomously spreading across networks.
Researchers suggest these adaptive worms may soon challenge existing cybersecurity measures by changing tactics in real time and exploiting a broad spectrum of targets.
Mini dictionary: Shadowserver Foundation, a non-profit cybersecurity organization that actively monitors internet security threats and helps remediate large-scale malware and botnet infections by working with internet providers and law enforcement agencies around the world.
The next generation of malware, supercharged by artificial intelligence, poses a growing threat due to its ability to adapt instantly and operate without direct human intervention.





USDT
AAPL
