A large-scale botnet that targeted cryptocurrency users by intercepting payment transactions has been disrupted through an international law enforcement and industry effort. Security company CrowdStrike, which specializes in threat intelligence and cybersecurity solutions, worked with authorities in the United States and Europe to dismantle Sality, a malware network that has operated for nearly two decades.
Clipboard hijacking exposed
Sality was notorious for distributing a malicious payload named EggJagger, which targeted Windows computers. The malware actively monitored the clipboard for copied Bitcoin or Ether wallet addresses. When users copied a wallet address intending to send funds, EggJagger would replace the address in the clipboard with one under the attacker’s control, redirecting cryptocurrency payments to cybercriminals instead of intended recipients.
Sality enabled hackers to reroute payments by quietly switching wallet addresses every time a user copied an address to send Bitcoin or Ether, making even careful users susceptible to theft.
Checking only the first and last few characters of a wallet address provided no real safeguard, as the malware replaced the full address in a way that was virtually impossible to detect without thorough comparison.
CrowdStrike reported that, over an eight-year span, at least 12.1 million rubles, approximately $150,000, were stolen through these fraudulent transactions. By January 2025, the unspent value of the stolen cryptocurrency held by the operator had reached about 147 million rubles, or an estimated $1.35 million.
Mini dictionary: CrowdStrike is a US-based cybersecurity firm that provides threat intelligence, endpoint security, and incident response services to organizations worldwide. It is recognized for its work in detecting and mitigating advanced digital threats.
Architecture fueled Sality’s longevity
Unlike many past malware botnets, Sality operated without a central command server. Instead, it used a peer-to-peer structure: infected computers communicated directly with each other, periodically updating their list of active peers. This made the botnet difficult to dismantle, as law enforcement could not disable a single point of control.
Sality spread by attaching itself to executable files shared over networks and removable drives, replicating automatically and regenerating without manual intervention from its operators. The botnet accepted any machine that responded to its handshake protocol, lacking verification mechanisms for new peers. This inherent trust allowed analysts from CrowdStrike’s Counter Adversary Operations team to infiltrate the network. They manipulated the peer lists, removing legitimate connections and introducing their own controlled servers, known as sinkholes, to cut off contact with the attacker’s command infrastructure.
The disruption demonstrates how peer-to-peer botnets resist traditional takedown methods, but targeted intervention can isolate infected systems and weaken the operator’s control.
Authorities also pursued a parallel legal action. The Justice Department, FBI, and Defense Criminal Investigative Service seized Sality-related domains in the US, while police in Bulgaria, Hungary, and Romania coordinated similar actions in Europe. The nonprofit Shadowserver Foundation is cooperating with internet providers to notify affected victims.
Ongoing risk and remediation needs
CrowdStrike cautioned that cutting off the botnet’s command channel does not remove existing malware from infected computers. In other words, while the infrastructure behind Sality has been severely weakened, any devices already compromised must still be cleaned to remove the EggJagger payload and other potential threats.
Users and organizations are advised to thoroughly inspect their systems for signs of infection, remove malicious files, and audit devices for exposed credentials or misdirected payments. Maintaining up-to-date systems and cross-verifying entire wallet addresses, preferably on separate signing devices, can help mitigate risks going forward.
Mini dictionary: EggJagger is a clipboard-hijacking component of Sality that specifically monitors for cryptocurrency wallet addresses and swaps them for those controlled by the attacker, resulting in misdirected digital asset transfers.
| Aspect | Before Disruption | After Disruption |
|---|---|---|
| Infected machines | Over 33,000 | Contact with operator disrupted, infections persist |
| Control structure | Peer-to-peer, decentralized | Sinkhole servers intercept command channels |
| Stolen crypto value | $150,000 estimated stolen | Unspent portfolio peaked at $1.35 million |
Key lessons from the Sality case
The takedown highlights the resilience of decentralized botnets and the need for comprehensive response strategies. Stopping a malware operator’s instructions is a necessary step, but as long as infected devices remain, risks of continued theft and further system compromise persist.




