The U.S. Department of Justice and CrowdStrike teamed up to dismantle the Sality botnet, which had been operating for over 20 years
According to Decrypt, CrowdStrike and the U.S. Department of Justice announced on Tuesday that they have dismantled the Sality peer-to-peer botnet, which has been active since 2003.This botnet primarily hijacked cryptocurrency payments through the EggJagger malware over the past eight years, which monitored the cryptocurrency wallet addresses in victims' clipboards and replaced them with the operator's own address, causing victims to send funds to strangers.CrowdStrike estimates that the operator has stolen at least 12.1 million rubles (approximately $150,000) solely through the EggJagger payload. Most of the stolen cryptocurrency has not been spent, and CrowdStrike assesses that these unspent assets were worth about 147 million rubles (nominally around $1.35 million) at their peak in January 2025. The reason Sality has survived to this day is that it does not have a central server that can be seized; infected machines communicate directly with each other.This multinational operation involved the United States, Bulgaria, Hungary, and Romania. The U.S. Department of Justice, FBI, and Defense Criminal Investigative Service seized Sality-related domains within the United States, and police from multiple European countries also seized other domains.CrowdStrike isolated more than 15,000 infected machines to its controlled honeypot by exploiting its architectural vulnerabilities. The operator has been tracked as SALTY SPIDER, which launched a denial-of-service attack against the Russian cryptocurrency exchange AvanChange in September 2023.