Rows of servers in a data center representing infrastructure used by peer-to-peer botnets

Sality Botnet Cut Off After 23 Years of Crypto Address Hijacking

September 2, 2026 11:22 am Comments

One of the internet’s longest-running botnets has finally lost its command channel, but the infected computers it left behind are not magically clean.

The U.S. Department of Justice announced a multinational operation that disrupted Sality infrastructure in the United States and Europe. American authorities seized Sality-linked domains, while partners in Bulgaria, Hungary and Romania acted against additional infrastructure.

The operation brought together the FBI, the Defense Criminal Investigative Service, CrowdStrike, the Shadowserver Foundation, Europol, Eurojust and national law-enforcement agencies. DOJ said the partnership advanced the first pillar of President Trump’s Cyber Strategy for America: shaping adversary behavior by degrading malicious infrastructure.

Sality has been active since 2003. Its durability came from a peer-to-peer design that allowed infected machines to communicate directly instead of relying on one central server that investigators could seize.

DOJ said the owners of compromised computers were typically unaware that their devices had been folded into the botnet. The machines could then receive commands and support cryptocurrency theft or other cyberattacks without their owners’ knowledge.

The U.S. action was only one part of the operation. While American agencies seized domestic domains, European partners acted against Sality-linked domains hosted overseas and began the longer process of identifying victims who still need to remove the malware.

CrowdStrike said the botnet had delivered malicious payloads to more than 15,000 machines worldwide. Sality also infected executable files and spread through network shares, removable drives and file sharing, allowing infections to regenerate with little effort from the operator.

For the past eight years, Sality’s primary payload was EggJagger, a clipjacking tool built to watch a victim’s clipboard for cryptocurrency wallet addresses. When it detected a copied Bitcoin or Ethereum address, it could silently swap in an address controlled by the attacker before the victim completed the payment.

That distinction matters. The theft did not require breaking Bitcoin or Ethereum themselves.

It exploited a compromised computer at the moment a user prepared a transaction.

CrowdStrike estimated that EggJagger stole at least 12.1 million rubles, roughly $150,000, while the largely unspent portfolio later reached a much higher peak value. That estimate covered EggJagger alone; Sality had also distributed credential stealers, spam tools, proxies, network-exploitation payloads and software used in distributed denial-of-service attacks.

The takedown succeeded by attacking the botnet’s peer lists. Sality machines periodically checked a finite list of publicly reachable “super peers.”

Investigators manipulated that process, invalidated legitimate criminal peers and inserted defender-controlled sinkholes into the emptied lists.

As infected machines contacted those sinkholes during normal maintenance cycles, they became isolated from the operator. That stopped new payload instructions and direct payload transfers from moving through the network.

At the same time, authorities and private partners took down URLs that hosted Sality payloads. The Shadowserver Foundation is now working with internet service providers and incident-response teams to identify infected systems and notify victims.

The important warning is what the operation did not do. It did not uninstall Sality or EggJagger from compromised computers.

A machine can remain infected even though its connection to the criminal operator has been cut.

Crypto users should treat copied wallet addresses as a security boundary, not a harmless convenience. Checking the complete destination address on a trusted device before signing a transaction remains essential, especially when a computer shows unexplained security alerts or unusual network behavior.

Sality survived for 23 years by avoiding a central point of failure. Investigators eventually found a different pressure point: the trust that every infected machine placed in its peers.

The botnet’s decentralized architecture kept it alive for decades, and in the end that same architecture gave defenders the route inside.

Join the conversation!

We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.