The Justice Department and CrowdStrike announced Tuesday the disruption of Sality, a peer-to-peer botnet that has circulated since 2003. The malware spent its final eight years hijacking cryptocurrency payments by rewriting wallet addresses on infected computers through a tool called EggJagger.
How the Attack Worked
EggJagger operated as a clipjacking tool that monitored the clipboard for cryptocurrency wallet addresses and replaced them with the operator's own addresses. When a victim copied a Bitcoin or Ethereum address to make a payment, the funds were sent to the attacker instead of the intended recipient.
CrowdStrike estimates the operator stole at least $150,000 through EggJagger alone. Before deploying this cryptocurrency theft tool, the botnet delivered credential theft, spam, proxy services, and denial-of-service payloads.
Unclaimed Gains
The stolen cryptocurrency was largely left untouched by the operator. CrowdStrike valued the unspent portfolio at approximately 147 million rubles in January 2025, equivalent to roughly $1.35 million at that time.
Why Sality Persisted
Sality survived for over two decades because it lacked a central server vulnerable to seizure. Infected machines communicated directly with one another, and the malware spread by attaching itself to executable files shared over network drives and removable media. This decentralized structure allowed the botnet to regenerate without active effort from its operator.
Dismantling the Network
CrowdStrike's Counter Adversary Operations team exploited the botnet's open architecture to disrupt it. The peer-to-peer network accepted any machine that answered the handshake correctly with no verification of identity. CrowdStrike isolated more than 15,000 infected machines worldwide by removing legitimate peers from each bot's address list and inserting its own sinkholes.
The Justice Department, FBI, and Defense Criminal Investigative Service seized Sality-linked domains in the United States. Law enforcement in Bulgaria, Hungary, and Romania took down additional infrastructure in Europe. The Shadowserver Foundation is notifying victims through internet service providers.
Operator Activity
CrowdStrike tracks the botnet's operator as SALTY SPIDER. The operator occasionally weaponized the botnet against other targets, including a denial-of-service attack on AvanChange, a Russian cryptocurrency exchange, in September 2023. CrowdStrike believes the operator used such exchanges to convert stolen coins into cash.
Infected machines now report to CrowdStrike-controlled sinkholes rather than their original operator. CrowdStrike has published detection rules and network indicators. The company warns that malware already resident on compromised machines remains active until manually removed.


