A long-running botnet used to redirect cryptocurrency payments has been disrupted, but infected computers still need to be cleaned. Sality distributed a payload called EggJagger that replaced Bitcoin and Ether wallet addresses copied to the Windows clipboard with addresses controlled by an attacker.
CrowdStrike’s September 1 technical report dates the coordinated operation to August 31, 2026. It says the botnet had enabled payload distribution to more than 33,000 infected machines. The company worked with US and European law enforcement and industry partners to disrupt its command channel.

A clipboard attack anyone can fall for
Clipjacking exploits an ordinary payment workflow: copying an address and pasting it into a wallet. If malware changes the clipboard between those steps, the transaction can point to the wrong recipient even though the sender initially copied the correct address. Checking only a few characters is not a reliable safeguard.
CrowdStrike estimates at least 12.1 million rubles, roughly $150,000, in stolen value over eight years. It says the operator retained much of the cryptocurrency and that the unspent portfolio reached about 147 million rubles in January 2025. Stolen value and the later valuation of retained coins are different measures, so they should not be described as the same loss figure.
Why Sality survived for two decades
Sality endured because it had no head to cut off. The botnet has no central server to seize. Infected machines talk directly to one another, checking roughly every 40 minutes which known peers remain online, and the malware spreads by attaching itself to executable files passed over network shares and removable drives, regenerating without any effort from its operator. Before EggJagger, it earned its keep delivering credential theft, spam, proxy services and denial-of-service payloads.

That architecture was also the way in. Bots accepted any reachable machine that answered the handshake correctly, with no verification of who was joining. CrowdStrike’s Counter Adversary Operations team used that trust against the network, stripping legitimate peers from each bot’s address list and inserting its own sinkhole servers. The aim is to prevent infected peers from receiving further instructions from the operator.
The legal arm moved in parallel. The Justice Department, FBI and Defense Criminal Investigative Service seized Sality-linked domains in the United States, while police in Bulgaria, Hungary and Romania took down others in Europe. The Shadowserver Foundation is working with internet providers to notify victims. CrowdStrike has published detection rules and network indicators, with a caveat: malware already sitting on infected machines stays active until someone removes it.

What the case teaches
The disruption illustrates why stopping a command channel is only one stage of incident response. Existing malicious files may remain on a device after its contact with the botnet is interrupted. Users and organizations still need to identify affected systems, remove the infection and assess whether credentials or payment information were exposed.
Frequently asked questions
What is the Sality botnet?
A peer-to-peer botnet circulating since 2003 that delivered other criminals’ payloads. For the last eight years its primary cargo was EggJagger, a tool that hijacked cryptocurrency payments on infected machines.
How did EggJagger steal crypto?
It monitored the Windows clipboard and, when it detected a copied bitcoin or ether address, silently replaced it with an address controlled by the attacker. Victims who pasted and sent paid the attacker instead of their intended recipient.
How much was stolen?
CrowdStrike estimates at least 12.1 million rubles, about $150,000, over eight years. Because the operator rarely spent the coins, the unspent holdings peaked at roughly $1.35 million in January 2025.
How was the botnet taken down?
The operation manipulated peer discovery so that infected systems contacted sinkhole infrastructure. CrowdStrike describes this as disrupting the operator’s command channel, while warning that existing malware still requires removal.
Who was behind it?
The report describes the operator’s activity, but disruption of infrastructure should not be confused with a confirmed arrest or a court finding against a named individual.
How can users protect themselves?
Verify the entire destination address against a trusted source and, where available, on a trusted signing device. Keep systems updated and investigate unexpected address changes. Do not continue signing transactions on a machine suspected of infection. TBJ’s hardware-wallet guide explains the role of a separate signing device; it is not a substitute for checking the recipient.
Risk disclosure
Clipboard-hijacking malware is one of many attack vectors targeting cryptocurrency users, and transactions sent to a wrong address are generally irreversible. Figures cited from security researchers are estimates. This article does not constitute security advice for any specific system or situation.
Disclaimer: This article is for informational purposes only and does not constitute investment, legal or tax advice. Digital assets are volatile and may be subject to regulatory restrictions in your jurisdiction. Always do your own research and consult a licensed professional before making financial decisions.

