< Back to all clusters
[TECHNOLOGY] · United States, Bulgaria, Hungary, Romania · 12 sources

started · updated

Sality botnet dismantled in multinational cybercrime operation

A multinational law enforcement operation has successfully disrupted the Sality botnet, a Russia-based peer-to-peer malware network that has been active since 2003. The coordinated effort involved the U.S. Department of Justice, FBI, and authorities from Bulgaria, Hungary, and Romania, with support from Europol, Eurojust, CrowdStrike, and the Shadowserver Foundation.

Sality was uniquely resilient due to its decentralized architecture, which allowed infected machines to communicate directly without a central command server. To dismantle the network, cybersecurity experts at CrowdStrike exploited a lack of identity authentication in the protocol, replacing trusted peers with sinkholes. This effectively cut off the botnet's operators from the infected devices.

For the past eight years, the botnet's primary function was cryptocurrency theft via a payload known as EggJagger. This tool used “clipjacking” to monitor the clipboard and replace Bitcoin or Ethereum wallet addresses with those controlled by criminals. CrowdStrike estimates that this method alone stole at least $150,000 in cryptocurrency, though the value of dormant stolen assets peaked at approximately $1.5 million in early 2025. While the operation has neutralized the current control structure, officials noted that existing infections on computers may still require remediation.

Entities

CrowdStrike · Europol · Nanjing Xinjiuwei Network Technology Co. · QTFY · Sality · Sality · Shadowserver Foundation · U.S. Department of Justice

Claims

What the coverage asserts, and how many sources carry each claim.