U.S. cybersecurity firm CrowdStrike and federal law enforcement have dismantled Sality, a botnet that has operated since 2003 and spent its last 8 years hijacking cryptocurrency payments on infected computers.
The attack it delivered is simple enough that most crypto users are exposed to it. Wallet addresses are long strings nobody types by hand, so people copy and paste them.
Sality's main payload, which CrowdStrike called ‘EggJagger,’ sat on infected machines, watching the clipboard, and when it saw something resembling a bitcoin or ether address, it replaced the copied text with an address belonging to the attacker.
A victim pasting into their wallet and hitting send paid a malicious actor, with no warning and nothing to undo. A defense for users is to check the first and last characters of an address after pasting it, every time.
CrowdStrike estimated that the attackers stole at least 12.1 million rubles, roughly $150,000, over eight years. Much of the crypto was left untouched, and the value of those unspent holdings later rose to as much as $1.35 million in early 2025 as crypto prices climbed.
While the number is relatively small, it shows how a simple trick worked for eight years — just exploiting everyday users who copied long wallet addresses rather than typing or closely inspecting them.
As such, Sality had no central server to seize. Infected machines talked directly to one another, checking every 40 minutes whether their known peers were still online, and the malware spread by attaching itself to programs shared on network drives and USB drives, regenerating without any effort from its malicious operator.
Any computer that responded in the expected way was treated as part of the botnet, with no further identity check.
CrowdStrike used that flaw to replace the real peer addresses with its own servers, cutting off more than 15,000 infected machines from the network. The operation was carried out on Monday during a live demonstration at CrowdStrike’s Day Zero summit in Las Vegas, authorities said.
The department said the operation was based in Russia.
coindesk.com