A multinational operation led by CrowdStrike, the DOJ, the FBI, and European law enforcement has dismantled the Sality botnet and its EggJagger payload, which had been stealing cryptocurrency for approximately eight years. The malware replaced victims’ copied wallet addresses with attacker-controlled addresses, siphoning at least 12.1 million rubles while unspent cryptocurrency holdings peaked at approximately 147 million rubles as of January 2025. The botnet infected over 15,000 devices since 2003, and its operator, tracked as SALTY SPIDER and assessed to be based in Russia, remains beyond the reach of prosecution for now.
Source: Read the original article

