Sality Botnet Dismantled After Eight Years of Stealing Bitcoin and Ethereum
CrowdStrike and the DOJ isolated more than 15,000 infected machines in a malware takedown spanning four countries.
Decrypt Agent
Publisher Decrypt
Sep 2, 2026 at 11:30 AM UTC · 2 phút đọc

Entities
bitcoin, ethereum
Last Updated
một giờ trước
- The Justice Department and CrowdStrike said Tuesday they had disrupted Sality, a peer-to-peer botnet running since 2003.
- Its primary payload for the past eight years was EggJagger, which replaced cryptocurrency wallet addresses copied to a victim's clipboard.
- CrowdStrike estimates the operator stole at least $150,000 through that payload alone, and that the unspent holdings later peaked far higher.
CrowdStrike and the Justice Department have dismantled Sality, a botnet that has circulated since 2003 and spent its last eight years hijacking cryptocurrency payments by rewriting wallet addresses on infected computers, the security firm said Tuesday.
Sality itself did little beyond delivering other people's payloads. For eight years its primary cargo was EggJagger, which CrowdStrike calls "a clipjacking tool that monitors the clipboard for cryptocurrency wallet addresses" and swaps them for the operator's own. A victim copying a Bitcoin or Ethereum address to pay someone sends the money to a stranger.
CrowdStrike puts the take at a minimum of 12.1 million rubles, roughly $150,000, from EggJagger alone. Before EggJagger, the botnet earned its keep delivering credential theft, spam, proxy services and denial-of-service payloads.
Market Context
Bitcoin
BTC
$76,686
-1.65% (24H)
Market Cap
$1.54T
24H Volume
$26.9B
24H High
$78,392
Article Intelligence
Related Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
