Sality Botnet Isolated After Eight Years of Swapping Wallet Addresses

A botnet running since 2003 was cut off from its operator on 31 August. CrowdStrike and law enforcement in four countries redirected Sality's infected machines to servers under their own control, isolating more than 15,000 of them. For the past eight years the network's main payload watched for cryptocurrency wallet addresses copied to a victim's clipboard and substituted one the operator controlled. Confirmed theft through it comes to about $150,000. No arrest is reported in any account.
How the machines were taken away
Sality held together through peer-to-peer design, with no central server to seize. Each infected machine kept a list of peers and checked that list every 40 minutes. Investigators used the clock against it. They stripped the legitimate peers out and inserted their own sinkholes, servers substituted for a botnet's infrastructure so infected machines report to investigators and stop receiving instructions. Two separate networks, versions 3 and 4, went down at once. BleepingComputer adds that the operation went after known super peers and blocked both direct payload transfers and the instructions to download them. CrowdStrike published the sinkhole address so defenders can spot an infected machine by the traffic it sends there.
"This operation demonstrates that P2P architecture, long considered a shield against disruption, is not invincible," CrowdStrike said.
What the payload did
CrowdStrike calls the payload EggJagger and describes it as "a clipjacking tool that monitors the clipboard for cryptocurrency wallet addresses and silently replaces them with addresses controlled by the operator". BleepingComputer and Decrypt both carry that sentence unchanged. The attack works because a wallet address is too long to check by eye, so someone pasting one into a send field rarely reads it back. Nothing has to be broken for it to succeed. Supply-chain attacks reach the same money by a different road, and this desk covered one when Injective's npm package was backdoored to steal seed phrases.
Two money figures that measure different things
The theft attributed to EggJagger is 12.1 million rubles, given as about $150,000. Separately, the unspent balance sitting in Sality-controlled wallets peaked at 147 million rubles in January 2025, or roughly $1.35 million. Those are not the same measurement and no account merges them. CrowdStrike adds that the second figure was worth about the purchasing power of $4 million in Western capitals, and Decrypt repeats it; the other accounts leave it out. That is a comparison, not a market value. What no account says is how much of the balance was recovered, or whether any wallet was seized.
The machine count needs the same care. The 15,000 figure is the one every account carries. The Crypto Times prints two more and is alone in doing so: about 11 million unique IP addresses linked to Sality over its life, attributed to Europol, and roughly a million machines under the operator's control at peak. That account states plainly that its 15,000 is a current count and the other two are historical. Treating the three as one number would overstate what was cut off this week. August was the busiest month of 2026 for crypto incidents on one security firm's count, and the two tallies published for it disagree by about $79 million. Endpoint malware sits outside those tables entirely.
The infections do not end with the takedown
Cutting a botnet off its operator is not the same as cleaning the machines. Fifteen thousand computers are still infected. They now talk to a sinkhole instead of a controller. Nothing published describes how they get cleaned. CrowdStrike tracks the operator as SALTY SPIDER and assesses it as likely working from the Republic of Bashkortostan; BleepingComputer carries that assessment with the same hedge, and Crypto Briefing renders it without the regional detail. First Assistant United States Attorney Bill Essayli said cybercriminals, botnets and malware are "a clear and present danger to our nation's security and economy". No charge has been announced against anyone. Whether the operator can rebuild depends on how much of the peer network survived outside the sinkhole. Nothing published so far answers that.
Read also: A 2021 Firmware Flaw Drains 594 BTC From Coldcard Wallets