Crypto: The Sality Network Falls After Eight Years of Bitcoin and Ethereum Thefts
The dismantling of Sality ends a long cryptocurrency hijacking operation. This botnet, active since 2003, spent its last eight years stealing bitcoins and Ethers. Its method relied on a simple technique: modifying wallet addresses copied on infected machines. CrowdStrike and the U.S. Department of Justice coordinated the operation. This globally conducted operation isolated more than 15,000 machines across several regions of the world. The crypto phenomenon was at the heart of this activity.

In Brief
- Sality, a botnet active since 2003, was dismantled after eight years of Bitcoin and Ethereum diversions.
- EggJagger replaced wallet addresses copied by victims to divert their payments.
- CrowdStrike estimates losses related to EggJagger at at least 12.1 million rubles, about $150,000.
- The operation isolated more than 15,000 infected machines worldwide.
A Botnet That Diverts Bitcoin and Ethereum Payments
Sality operated as a network of infected machines that communicated directly with each other. For eight years, its main tool, EggJagger, monitored the clipboards of compromised computers. When a victim copied a Bitcoin or Ethereum address, the program replaced it with that of the operator. The payment then went to another address.
This method did not directly alter a transaction on a blockchain. The botnet intervened before sending when the user was preparing their payment. CrowdStrike estimates that EggJagger caused at least 12.1 million rubles in losses. This sum represents about $150,000 in the crypto sector.
Before EggJagger, Sality already exploited several criminal revenue sources. The network was notably used for credential theft, spam, proxy services, and denial-of-service attacks. Its crypto activity marked a model evolution. The operator then kept a large part of the stolen assets.
An Architecture That Complicated the Dismantling
Sality resisted due to an architecture without a central exploitable server. Infected machines exchanged information directly, complicating intervention. The malware spread via executable files on network shares and removable drives. It could regenerate automatically.
The botnet accepted accessible machines that responded correctly to its authentication mechanism. However, it did not verify the identity of new users. CrowdStrike exploited this weakness to remove legitimate peers from the infected machines’ address lists. It added its own blocking points to isolate more than 15,000 computers.
The operation involved multiple authorities. According to the Justice Department statement, the FBI and Defense Criminal Investigative Service seized domains associated with Sality in the USA. In Europe, Bulgarian, Hungarian, and Romanian police dismantled other infrastructures. The Shadowserver Foundation works with providers to inform victims in the crypto ecosystem.
Stolen Cryptos Still Largely Intact
The Sality botnet left behind a wallet containing a large part of the stolen cryptocurrencies. CrowdStrike valued these funds at about 147 million rubles in January 2025. This value represented about $1.35 million. This sum also corresponded to a purchasing power of four million dollars in a Western capital.
SALTY SPIDER has also used its network against certain targets. In September 2023, a denial-of-service attack notably targeted AvanChange, a Russian cryptocurrency exchange platform. CrowdStrike indicates that the malware code was compiled seconds before it was released online. It interprets this timing as an impulsive reaction to a personal grievance.
After the intervention, infected machines now send their information to test servers controlled by CrowdStrike. The company published detection rules and network indicators. Already installed malware remains active until removed. The botnet therefore does not automatically disappear from devices after dismantling.
In the short term, the intervention alters Sality’s communications and limits its control over machines. The retained funds remain a central element of the crypto scam case. Monitoring infections and removing software will now determine the operation’s scope. The Sality botnet thus enters a new phase, marked by the isolation of its machines and monitoring of its traces.
Maximize your Cointribune experience with our "Read to Earn" program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.
Journaliste et rédacteur web passionné par l’univers des cryptomonnaies et des technologies Web3. J’y traite les dernières tendances et actualités afin de proposer un contenu de haute qualité à un large public du secteur.
The views, thoughts, and opinions expressed in this article belong solely to the author, and should not be taken as investment advice. Do your own research before taking any investment decisions.