COINTURK NEWSCOINTURK NEWSCOINTURK NEWS
  • Crypto Tracker App
  • Bitcoin
  • Altcoin
  • Ethereum
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Search
© 2024 COINTURK NEWS. All Rights Reserved.
Reading: CrowdStrike disrupts Sality botnet tied to $150,000 in stolen crypto payments
Share
Font ResizerAa
COINTURK NEWSCOINTURK NEWS
Font ResizerAa
Search
  • Crypto Tracker App
  • Bitcoin
  • Altcoin
  • Ethereum
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Follow US
© 2025 >> COINTURK NEWS
Powered by LK SOFTWARE
COINTURK NEWS > Cryptocurrency News > CrowdStrike disrupts Sality botnet tied to $150,000 in stolen crypto payments
Cryptocurrency News

CrowdStrike disrupts Sality botnet tied to $150,000 in stolen crypto payments

In Brief

  • 🚨 CrowdStrike disrupts Sality botnet tied to $150,000 stolen in $BTC and Ether payments.

  • 🛡️ The botnet hijacked clipboard wallet addresses, redirecting crypto to attackers.

  • 💻 Over 33,000 devices remain infected and require urgent malware removal.

  • 📅 Sality operated for nearly 20 years before the international takedown action.
Dr. Levent Kurt
Dr. Levent Kurt 3 hours ago
Share
SHARE

A large-scale botnet that targeted cryptocurrency users by intercepting payment transactions has been disrupted through an international law enforcement and industry effort. Security company CrowdStrike, which specializes in threat intelligence and cybersecurity solutions, worked with authorities in the United States and Europe to dismantle Sality, a malware network that has operated for nearly two decades.

Contents
Clipboard hijacking exposedArchitecture fueled Sality’s longevityOngoing risk and remediation needsKey lessons from the Sality case

Clipboard hijacking exposed

Sality was notorious for distributing a malicious payload named EggJagger, which targeted Windows computers. The malware actively monitored the clipboard for copied Bitcoin or Ether wallet addresses. When users copied a wallet address intending to send funds, EggJagger would replace the address in the clipboard with one under the attacker’s control, redirecting cryptocurrency payments to cybercriminals instead of intended recipients.

Sality enabled hackers to reroute payments by quietly switching wallet addresses every time a user copied an address to send Bitcoin or Ether, making even careful users susceptible to theft.

Checking only the first and last few characters of a wallet address provided no real safeguard, as the malware replaced the full address in a way that was virtually impossible to detect without thorough comparison.

CrowdStrike reported that, over an eight-year span, at least 12.1 million rubles, approximately $150,000, were stolen through these fraudulent transactions. By January 2025, the unspent value of the stolen cryptocurrency held by the operator had reached about 147 million rubles, or an estimated $1.35 million.

Mini dictionary: CrowdStrike is a US-based cybersecurity firm that provides threat intelligence, endpoint security, and incident response services to organizations worldwide. It is recognized for its work in detecting and mitigating advanced digital threats.

Architecture fueled Sality’s longevity

Unlike many past malware botnets, Sality operated without a central command server. Instead, it used a peer-to-peer structure: infected computers communicated directly with each other, periodically updating their list of active peers. This made the botnet difficult to dismantle, as law enforcement could not disable a single point of control.

Sality spread by attaching itself to executable files shared over networks and removable drives, replicating automatically and regenerating without manual intervention from its operators. The botnet accepted any machine that responded to its handshake protocol, lacking verification mechanisms for new peers. This inherent trust allowed analysts from CrowdStrike’s Counter Adversary Operations team to infiltrate the network. They manipulated the peer lists, removing legitimate connections and introducing their own controlled servers, known as sinkholes, to cut off contact with the attacker’s command infrastructure.

The disruption demonstrates how peer-to-peer botnets resist traditional takedown methods, but targeted intervention can isolate infected systems and weaken the operator’s control.

Authorities also pursued a parallel legal action. The Justice Department, FBI, and Defense Criminal Investigative Service seized Sality-related domains in the US, while police in Bulgaria, Hungary, and Romania coordinated similar actions in Europe. The nonprofit Shadowserver Foundation is cooperating with internet providers to notify affected victims.

Ongoing risk and remediation needs

CrowdStrike cautioned that cutting off the botnet’s command channel does not remove existing malware from infected computers. In other words, while the infrastructure behind Sality has been severely weakened, any devices already compromised must still be cleaned to remove the EggJagger payload and other potential threats.

Users and organizations are advised to thoroughly inspect their systems for signs of infection, remove malicious files, and audit devices for exposed credentials or misdirected payments. Maintaining up-to-date systems and cross-verifying entire wallet addresses, preferably on separate signing devices, can help mitigate risks going forward.

Mini dictionary: EggJagger is a clipboard-hijacking component of Sality that specifically monitors for cryptocurrency wallet addresses and swaps them for those controlled by the attacker, resulting in misdirected digital asset transfers.

AspectBefore DisruptionAfter Disruption
Infected machinesOver 33,000Contact with operator disrupted, infections persist
Control structurePeer-to-peer, decentralizedSinkhole servers intercept command channels
Stolen crypto value$150,000 estimated stolenUnspent portfolio peaked at $1.35 million

Key lessons from the Sality case

The takedown highlights the resilience of decentralized botnets and the need for comprehensive response strategies. Stopping a malware operator’s instructions is a necessary step, but as long as infected devices remain, risks of continued theft and further system compromise persist.

You can follow our news on X, Telegram, Facebook & Coinmarketcap

You Might Also Like

Irish gangs use rented safe deposit boxes to hide crypto keys, CAB warns

EGRAG CRYPTO sets XRP targets up to $27 for Wave 5 macro cycle

Zcash ETF inflows surge as privacy coins outperform Bitcoin and wider crypto sector

Ireland’s Criminal Assets Bureau seizes first Bitcoin wallet in €360 million crypto crackdown

South Korea orders residents to report overseas crypto even if exchange fails

Dr. Levent Kurt 7 September, 2026 - 9:26 pm 7 September, 2026 - 9:26 pm
Share This Article
Facebook Twitter
Share
Dr. Levent Kurt
By Dr. Levent Kurt
Follow:
Levent Kurt, who has been closely following the cryptocurrency and blockchain ecosystem since 2013, is the Editor-in-Chief and Co-Founder of COINTURK.Kurt, who holds a Ph.D. in Data Science, conducts research on Bitcoin, altcoins, blockchain technologies, digital asset markets, data analysis, and global developments in the cryptocurrency sector. He is the author of “Cryptocurrency Bitcoin: In Pursuit of Financial Freedom”, published in 2015.In the news, analysis, and research published on COINTURK, he aims to provide readers with reliable and understandable information by combining a data-driven approach with market experience and an assessment of technological developments.
Previous Article XRP price rebounds to $1.3892 after heavy margin liquidations
Next Article Bitcoin trades at $79,105 as ETFs see $987 million inflow in three days
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Stay Connected

8.1k Like
21.1k Follow
1.1k Follow
⭐ Top Crypto Casinos ⭐

CB
Cloudbet BEST
VISIT

Latest News

Ethereum Foundation targets censorship resistance in Hegotá upgrade with 2 key EIPs
Ethereum (ETH)
Analyst says XRP enters buy zone after pulling back from 2025 high
Ripple (XRP)
//

COINTURK was launched in March 2014 by a group of technology enthusiasts who believe that Bitcoin will be as important as the internet in the world of the future thanks to the amazing technology underlying it.

CRYPTOCURRENCY LIVE PRICES

  • Bitcoin (BTC) Live Price
  • Ethereum (ETH) Live Price
  • Ripple (XRP) Live Price
  • Solana (SOL) Live Price
  • Dogecoin (DOGE) Live Price
  • Cardano (ADA) Live Price
  • Chainlink (LINK) Live Price

OUR PARTNERS

  • COINMARKETCAP
  • COINGECKO
  • BITCOINHABER
  • BH NEWS
  • NEWSLINKER

OUR COMPANY

  • About Us
  • Cookie Policy
  • Advertising
  • Contact
COINTURK NEWSCOINTURK NEWS
Follow US
COINTURK NEWS 2026
Welcome Back!

Sign in to your account

Lost your password?