CrowdStrike, in collaboration with U.S. and European law enforcement agencies, announced on September 2, 2026 that it had dismantled the Sality botnet, a malicious network operating from Russia and active since 2003. The operation severed more than 15,000 infected machines from the peer-to-peer botnet network, which had been stealing cryptocurrency for approximately eight years.
🔑 Key Takeaways
- The Sality botnet, active since 2003, stole at least $150,000 in BTC and ETH over 8 years through clipboard hijacking attacks
- CrowdStrike exploited a P2P protocol flaw to isolate more than 15,000 infected machines
- International cooperation between the DOJ, FBI, and Bulgarian, Hungarian, and Romanian police enabled the takedown
- The potential value of stolen assets reached $1.35 million at the January 2025 peak
Origins and Evolution of the Sality Botnet
Sality was first observed in 2003 as malware distributing programs through network shares and USB drives. After more than fifteen years of activity, the group behind the botnet shifted its operations toward cryptocurrency theft. For approximately eight years, the botnet’s main payload, designated EggJagger by CrowdStrike, carried out what experts call a « clipboard hijacking attack ». The malware monitored the clipboard of infected machines and, upon detecting text resembling a Bitcoin (BTC) or Ethereum (ETH) wallet address, automatically replaced it with an address controlled by the attackers. A user who then pasted the address into their wallet would send their funds to the hacker, without any warning.

Estimated Losses and Valuation of Stolen Assets
According to CrowdStrike’s estimates, this technique enabled the theft of at least 12.1 million rubles, approximately $150,000, over an eight-year period. A large portion of the stolen cryptocurrency was not touched; its value subsequently climbed with rising prices, reaching approximately $1.35 million (147 million rubles) at the January 2025 peak. This amount reflects the potential value of assets held by the attackers rather than profits actually realized.
| Period | Amount Stolen (estimate) | USD Equivalent |
|---|---|---|
| 8 years of activity (2018-2026) | 12.1 million RUB | ~$150,000 |
| Value at peak (January 2025) | 147 million RUB | ~$1.35 million |
Decentralized Architecture and Takedown Method
The Sality botnet distinguished itself through its decentralized architecture: it had no central server that could be seized. Infected machines communicated directly with each other, checking every 40 minutes whether their peers were still online. The malware propagated by attaching itself to programs shared on network drives and USB peripherals, regenerating without operator intervention. This design made the network resilient and difficult to dismantle using traditional methods.
« Any computer that responded in the expected way was treated as part of the botnet, with no further identity check. »
CrowdStrike, Technical Report
The operation’s success relied on a weakness in the botnet’s communication protocol. CrowdStrike exploited the fact that the botnet did not verify the identity of communicating nodes: any machine responding as expected was automatically considered a legitimate peer, without further verification. By replacing the addresses of legitimate peers with its own servers, the company successfully isolated more than 15,000 infected machines, depriving the operators of their ability to send new commands or malicious payloads.
International Coordination and Implications for Users
The action was coordinated internationally. The U.S. Department of Justice (DOJ) and FBI worked jointly with law enforcement from Bulgaria, Hungary, and Romania. Police in all four countries simultaneously seized infrastructure associated with the botnet. The DOJ stated that the operation was based in Russia.
« The attack is simple enough that most crypto users are exposed. »
CrowdStrike, EggJagger Report
The company recommended that users systematically verify the first and last characters of a wallet address after pasting it, to detect any malicious replacement. It also advised using up-to-date antivirus software to protect devices.
Naming Discrepancy and Key Lessons
A discrepancy exists in the naming of the malicious module. While CrowdStrike and several sources refer to it as EggJagger, the CoinNess site designates it as Egregor. This naming difference does not alter the software’s functionality, but illustrates the challenges of naming in the cybersecurity landscape.
Outlook and Conclusion
The takedown of Sality demonstrates that even decentralized criminal infrastructure active for more than twenty years can be compromised through cooperation between the private sector and authorities. It also underscores the importance for cryptocurrency users to carefully verify wallet addresses during each transaction, as device security is as crucial as private key security.
To date, no major reaction from the cryptocurrency market has been reported following this announcement. Bitcoin and Ethereum prices remained relatively stable in the hours following the publication of the information, according to available market data. Several scenarios remain possible: increased selling pressure if similar operations are announced, or stabilization around current levels in the absence of new developments.
Sources
This article is published for informational and educational purposes. It does not constitute investment advice in any way. Conduct your own research (DYOR) before making any decisions.

