Headlines

Sality Takedown Isolates 15,000 Machines Used in Crypto Theft


CrowdStrike and the U.S. Department of Justice disrupted the Sality botnet, isolating more than 15,000 infected machines that had been used to distribute malicious payloads. Active since 2003, Sality spent the past eight years primarily delivering EggJagger, a tool that monitored copied cryptocurrency wallet addresses and replaced them with addresses controlled by its operator.

The operation targeted a damaging weakness in cryptocurrency payment workflows. When malware changes an address before a payment is completed, funds can be redirected to a different recipient. CrowdStrike estimates that EggJagger alone was responsible for at least 12.1 million rubles, or roughly $150,000, in stolen cryptocurrency.

Sality was first observed in 2003 and evolved into a peer-to-peer botnet. Rather than relying on a central command-and-control server, infected machines communicated directly with one another. The malware also spreads by attaching itself to executable files shared through network shares, removable drives, and file sharing.

According to CrowdStrike, Sality’s technical role was to deploy additional payloads to infected machines. EggJagger became its primary payload over the past eight years.

The clipjacking tool monitored a victim’s clipboard for cryptocurrency wallet addresses and silently replaced them with an address controlled by the operator. A person copying a Bitcoin or Ethereum address to make a payment could therefore have funds redirected away from the intended recipient.

This mechanism differs from an exchange breach or a smart-contract exploit. It involved the device and clipboard used in the process of preparing a cryptocurrency payment, rather than an attack on the blockchain itself.

Trade XRP on ByBit and Join 99Bitcoin’s Exclusive $1000 USDT Airdrop Campaign

What the Takedown Proves, and What It Does Not

CrowdStrike’s Counter Adversary Operations team used Sality’s peer-to-peer design against the botnet. The operation manipulated peer lists by removing legitimate peers and inserting CrowdStrike-controlled sinkholes. This isolated infected machines from the operator’s control and prevented the botnet from receiving new tasking.

The U.S. Department of Justice, FBI, and Defense Criminal Investigative Service took action against Sality-linked infrastructure in the United States. Law-enforcement partners in Bulgaria, Hungary, and Romania supported related action in Europe. The Shadowserver Foundation is working with internet providers to notify victims.

The Sality botnet takedown isolated over 15,000 machines, but EggJagger malware remains active and can redirect crypto payments.
Agents at the FBI’s cyber division headquarters monitor global data streams in real-time.

CrowdStrike tracks the operator as SALTY SPIDER. The firm said the stolen cryptocurrency was largely left unspent, with the portfolio reaching a peak value of about 147 million rubles in January 2025, nominally around $1.35 million.

Disrupting the operator’s control channel does not remove malware from compromised systems. CrowdStrike said that malware already present on infected machines remains active until it is removed, meaning affected systems still require remediation.

EXPLORE: Best Crypto Presales With Asymmetric Upside in the Current Market

Why the Theft Matters for Crypto Users

The confirmed EggJagger theft total is limited to one payload family, but the mechanism shows how malware can interfere with a routine payment workflow. A copied address can originate from a legitimate source, while the clipboard content is altered on an infected device before a transaction is completed.

The more than 15,000 machines isolated during the operation illustrate the scale of the infrastructure CrowdStrike addressed. The case centers on clipboard substitution: malware monitored cryptocurrency wallet addresses and replaced them with addresses controlled by the operator, redirecting payments made from infected computers.

The Sality botnet takedown isolated over 15,000 machines, but EggJagger malware remains active and can redirect crypto payments.

Bitcoin and the Sality Disruption

Bitcoin’s market context and the Sality operation are separate issues. The botnet used cryptocurrency addresses as part of its theft scheme, but the evidence surrounding the disruption does not establish a connection between the operation and Bitcoin’s market direction.

Market Cap





The takedown is instead a cybersecurity development involving the safety of payment workflows on compromised devices. Its immediate effect, according to CrowdStrike, was to isolate infected machines so that the operator could no longer communicate with them or issue new instructions.

For cryptocurrency users, the central issue is not a change to the underlying blockchain. It is the risk that malware on a device can alter payment information during a transaction workflow. The continuing presence of malware on affected machines also means the disruption did not itself clean those systems.

MEXC

4.7
MEXC is our favourite full-suite crypto exchange offering trading, staking, airdrops and more

Visit MEXC

Follow 99Bitcoins on X For the Latest Market Updates and Subscribe on YouTube For Daily Expert Market Analysis.

 

The post Sality Takedown Isolates 15,000 Machines Used in Crypto Theft appeared first on 99Bitcoins.





Source link

Leave a Reply

Your email address will not be published. Required fields are marked *