United States federal authorities partnered with CrowdStrike, the Shadowserver Foundation, and law enforcement agencies from Bulgaria, Hungary, and Romania to disrupt the Sality botnet and its associated malware. The network had been planting malware on compromised devices since 2003, facilitating various cyberattacks alongside the theft of cryptocurrency from users worldwide.
Around 15,000 infected computers made up this peer-to-peer botnet network. Each machine in the network was programmed to check its online status every 40 minutes. This P2P communication model made the botnet more resilient against takedown efforts, as it operated without relying on a single central command server that law enforcement could easily track.
Address Hijacking via EggJagger
Over the past eight years, the threat actors behind Sality focused their exploits using a tool named EggJagger. The program operated as a clipboard hijacking tool lurking in the background of victim systems. Its primary objective was monitoring device memory activity for text matching cryptocurrency wallet address formats.
CrowdStrike explained that the theft relied on victim oversight. When users copied a Bitcoin or Ethereum address to make a payment, EggJagger detected the clipboard text and silently replaced it with an operator-controlled address. Users pasting the text often overlooked the long string of characters, redirecting funds directly to attackers once the network processed the transaction.
Millions in Untouched Balances
Sality operators accumulated at least 12.1 million rubles, or roughly $150,000 in cryptocurrency, over the eight-year period of using EggJagger. This recorded loss represented only a portion of the incoming fund flows to the perpetrators’ wallets.
CrowdStrike’s report uncovered dormant balances across the group’s wallet addresses, detecting digital assets categorized as never-spent that remained untouched. These idle holdings gradually accumulated, peaking at approximately $1.5 million in January 2025.
The international law enforcement intervention finally dismantled the two-decade-old botnet. The cybercriminals have now lost the ability to communicate with infected machines. Severing contact completely froze control of the network, freeing 15,000 devices from clipboard interception during crypto transactions. Reported by Cointelegraph.
Read also: Cronos Restarts via Forced Rollback - But $6 Million Already Escaped to Ethereum
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




