DOJ and CrowdStrike Take Down Sality, a Crypto-Hijacking Botnet
Key Takeaways
- Sality hijacked crypto payments for eight years by swapping copied wallet addresses in an infected computer’s clipboard.
- CrowdStrike exploited a peer-to-peer verification flaw to sinkhole the botnet, cutting off more than 15,000 infected machines.
- The DOJ, FBI and law enforcement in Bulgaria, Hungary and Romania coordinated the takedown, seizing Sality-linked domains.
The U.S. Department of Justice, the FBI, and cybersecurity firm CrowdStrike disrupted Sality, a Russia-based botnet that spent the past eight years hijacking cryptocurrency payments by silently swapping copied wallet addresses for ones controlled by attackers.
The joint operation, carried out Monday with law enforcement partners in Bulgaria, Hungary, and Romania, disconnected more than 15,000 infected machines from the network.
Malware Silently Swapped Copied Wallet Addresses
Sality’s core payload, which CrowdStrike named “EggJagger,” monitored an infected computer’s clipboard for text resembling a Bitcoin or Ethereum wallet address. When a user copied an address to send a payment, the malware quietly replaced it with an address belonging to the attacker before the user pasted it into their wallet software.
Because wallet addresses are long strings of characters that few people type manually or check closely, victims often completed the payment without noticing the substitution.
CrowdStrike estimated the operation stole at least 12.1 million rubles, roughly $150,000, over eight years. Much of the stolen cryptocurrency was never moved from the attackers’ wallets, and the value of those unspent holdings had climbed to as much as $1.35 million by early 2025 as crypto prices rose.
A Botnet With No Central Server to Seize
According to the Justice Department, Sality has installed malware on compromised devices since 2003, initially for other purposes before its operators shifted toward cryptocurrency theft.
The malware built what is known as a peer-to-peer botnet, a decentralized network in which infected computers communicate directly with one another rather than checking in with a central command server.
Infected machines checked roughly every 40 minutes to confirm that other known infected computers were still reachable, and the malware spread further by attaching itself to files shared over network drives and USB drives.
That structure meant there was no single server for investigators to seize in order to shut the network down.
Investigators Exploited a Peer-to-Peer Flaw to Cut Off the Network
CrowdStrike’s Counter Adversary Operations team identified a flaw in how infected machines verified other peers on the network: any computer that responded in the expected way was accepted as a legitimate part of the botnet, with no further identity check.
CrowdStrike used that gap to insert its own servers into the network in place of genuine infected peers, a technique known as a sinkhole operation, cutting off more than 15,000 compromised machines from further instructions. The operation was demonstrated live at CrowdStrike’s Day Zero security summit in Las Vegas.
International Law Enforcement Coordinated the Takedown
The Justice Department, FBI, and the Department of Defense’s Defense Criminal Investigative Service seized Sality-linked domains inside the United States, while law enforcement agencies in Bulgaria, Hungary, and Romania acted against related domains hosted in Europe.
First Assistant U.S. Attorney Bill Essayli said the operation demonstrated that coordinated action between government and industry “can be a powerful force for good.”
FBI Los Angeles Assistant Director in Charge Patrick Grandy said the collaboration “enhances the FBI’s cybersecurity capabilities and our efforts to neutralize the threat” posed by the botnet. The nonprofit Shadowserver Foundation is now working with internet service providers to identify remaining infections and help notify affected users.
Losses Were Small in Dollar Terms but the Method Persisted for Years
The roughly $150,000 in original losses attributed to Sality is modest compared with other cryptocurrency theft operations disrupted in recent years, but the case illustrates how a simple technique can persist for nearly a decade without detection.
Security researchers recommend checking the first and last several characters of a wallet address after pasting it and before confirming any cryptocurrency transaction, since clipboard-hijacking malware of this kind typically substitutes an address that looks similar at a glance.