started · updated
Sality botnet dismantled in multinational cybercrime operation
A multinational law enforcement operation has successfully disrupted the Sality botnet, a Russia-based peer-to-peer malware network that has been active since 2003. The coordinated effort involved the U.S. Department of Justice, FBI, and authorities from Bulgaria, Hungary, and Romania, with support from Europol, Eurojust, CrowdStrike, and the Shadowserver Foundation.
Sality was uniquely resilient due to its decentralized architecture, which allowed infected machines to communicate directly without a central command server. To dismantle the network, cybersecurity experts at CrowdStrike exploited a lack of identity authentication in the protocol, replacing trusted peers with sinkholes. This effectively cut off the botnet's operators from the infected devices.
For the past eight years, the botnet's primary function was cryptocurrency theft via a payload known as EggJagger. This tool used “clipjacking” to monitor the clipboard and replace Bitcoin or Ethereum wallet addresses with those controlled by criminals. CrowdStrike estimates that this method alone stole at least $150,000 in cryptocurrency, though the value of dormant stolen assets peaked at approximately $1.5 million in early 2025. While the operation has neutralized the current control structure, officials noted that existing infections on computers may still require remediation.
Entities
CrowdStrike · Europol · Nanjing Xinjiuwei Network Technology Co. · QTFY · Sality · Sality · Shadowserver Foundation · U.S. Department of Justice
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 4 SOURCES] The takedown was achieved by replacing trusted peers in the peer-to-peer network with sinkholes. itnerd.blog · www.nationaltechnology.co.uk · blockcast.it · cybernoz.com
- [● 6 SOURCES] Sality had distributed malicious payloads to more than 15,000 infected machines worldwide. itnerd.blog · www.nationaltechnology.co.uk · blockcast.it · www.spacemoney.com.br · www.cointribune.com · +1 more
- [○ 1 SOURCE] The Sality botnet takeover was the most complex operation the company has ever conducted. www.nationaltechnology.co.uk
- [● 7 SOURCES] The EggJagger payload stole at least $150,000 in cryptocurrency by swapping wallet addresses. itnerd.blog · blockcast.it · bitcoinethereumnews.com · www.cryptobreaking.com · www.spacemoney.com.br · +2 more
- [○ 1 SOURCE] Hackers began focusing on cryptocurrency theft using the botnet around 2017. livecoins.com.br
- [● 11 SOURCES] The Sality botnet has been active and infecting computers since 2003. itnerd.blog · livecoins.com.br · www.nationaltechnology.co.uk · blockcast.it · cybernoz.com · +6 more