Sality Botnet Dismantled After Eight Years of Stealing Bitcoin and Ethereum

Sality Botnet Dismantled After Eight Years of Stealing Bitcoin and Ethereum

In brief The Justice Department and CrowdStrike said Tuesday they had disrupted Sality, a peer-to-peer botnet running since 2003. Its primary payload for the past eight years was EggJagger, which replaced cryptocurrency wallet addresses copied to a victim's clipboard. CrowdStrike estimates the operator stole at least $150,000 through that payload alone, and that the unspent holdings later peaked far higher. CrowdStrike and the Justice Department have dismantled Sality, a botnet that has circulated since 2003 and spent its last eight years hijacking cryptocurrency payments by rewriting wallet addresses on infected computers, the security firm said Tuesday.Sality itself did little beyond delivering other people's payloads. For eight years its primary cargo was EggJagger, which CrowdStrike calls "a clipjacking tool that monitors the clipboard for cryptocurrency wallet addresses" and swaps them for the operator's own. A victim copying a Bitcoin or Ethereum address to pay someone sends the money to a stranger. A multinational operation to disrupt the botnet and malware known as Sality and take down its infrastructure was announced today, involving actions in the United States, #Bulgaria, #Hungary, and #Romania, in collaboration with private industry partners CrowdStrike and the… pic.twitter.com/w34Bal8LG7 — FBI Los Angeles (@FBILosAngeles) September 1, 2026CrowdStrike puts the take at a minimum of 12.1 million rubles, roughly $150,000, from EggJagger alone. Before EggJagger, the botnet earned its keep delivering credential theft, spam, proxy services and denial-of-service payloads.What the operator never spentThe stolen coins were largely left untouched, which turned out to be the more profitable decision. CrowdStrike values the never-spent portfolio at a peak of about 147 million rubles in January 2025, a nominal $1.35 million, or roughly the purchasing power of $4 million in a Western capital.Sality survived since 2003 because it had no central server to seize. Infected machines talked directly to one another, and the malware spread by attaching itself to executable files passed over network shares and removable drives, regenerating without effort from its operator.Myriad: Bitcoin price next move? Click to make your prediction.That architecture was also the way in. Bots accepted any reachable machine that answered the handshake correctly, with no check on who was joining. CrowdStrike's Counter Adversary Operations team used that access to strip legitimate peers from each bot's address list and insert its own sinkholes, isolating more than 15,000 machines worldwide.The Justice Department, FBI and Defense Criminal Investigative Service seized Sality-linked domains in the U.S., while police in Bulgaria, Hungary and Romania took down others in Europe. The Shadowserver Foundation is working with internet providers to notify victims.The operator, whom CrowdStrike tracks as SALTY SPIDER, occasionally turned the botnet on targets of their own. A denial-of-service payload in September 2023 hit AvanChange, a Russian cryptocurrency exchange, and was compiled seconds before upload, which CrowdStrike reads as an impulsive response to a personal grievance. The firm believes the operator used exchanges like it to convert stolen coins into cash.Infected machines now report to CrowdStrike-controlled sinkholes rather than their owner. The company has published detection rules and network indicators, and warns that malware already sitting on those machines stays active until someone removes it.Daily Debrief NewsletterStart every day with the top news stories right now, plus original features, a podcast, videos and more.

Original Source

Read the full article at Decrypt →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.