Key Takeaways
- CrowdStrike partnered with U.S. authorities to dismantle Sality, a Russian botnet operating since 2003
- The operation utilized EggJagger malware to intercept and replace cryptocurrency wallet addresses copied by victims
- Approximately $150,000 worth of Bitcoin and Ethereum was stolen through clipboard manipulation over an eight-year period
- The value of unspent stolen cryptocurrency reached approximately $1.5 million in January 2025 due to market appreciation
- More than 15,000 compromised computers were disconnected from the malicious network in a coordinated takedown in Las Vegas
A partnership between [[LINK_START_0]]CrowdStrike[[LINK_END_0]] and United States federal authorities has successfully dismantled Sality, a sophisticated botnet operation that remained active for more than twenty years, dedicating its final eight years to stealing digital currency from unsuspecting victims.
The scheme functioned by monitoring clipboard activity on infected systems. Whenever a user copied a cryptocurrency wallet addressāwhether Bitcoin or Ethereumāto initiate a transfer, the malicious software instantly substituted it with an attacker-controlled address. Victims would unknowingly paste the fraudulent address and complete the transaction, sending their funds directly to cybercriminals.
The Technical Mechanics of the Attack
At the core of this theft operation was EggJagger, specialized clipjacking software that operated discreetly on compromised systems while continuously monitoring clipboard data.
Cryptocurrency wallet addresses consist of lengthy, complex character strings. Given their impractical length, virtually all users rely on copy-and-paste functionality rather than manual entry. This universal practice created the perfect vulnerability for exploitation.
The malware propagated through shared network directories and removable USB storage devices. It integrated itself into legitimate software applications and possessed self-regenerating capabilities that required no user interaction to maintain persistence.
Unlike traditional botnet architectures, Sality operated without a centralized command server, significantly complicating disruption efforts. The network functioned through direct peer-to-peer communication, with infected machines verifying the status of other compromised systems every 40 minutes.
The Takedown Strategy
CrowdStrike’s security researchers identified a critical vulnerability within the decentralized peer-to-peer architecture. By substituting legitimate peer addresses with company-controlled servers, the team successfully isolated over 15,000 infected machines from the broader network.
This disruption operation took place on Monday during a public demonstration at CrowdStrike’s Day Zero conference in Las Vegas.
The United States Department of Justice formally announced the successful operation on Tuesday. This international collaboration involved law enforcement agencies from Bulgaria, Hungary, and Romania, working alongside private sector entities including CrowdStrike and the Shadowserver Foundation.
According to the DOJ, the criminal infrastructure was based in Russia, with Sality deploying various forms of malware on infected systems since 2003.
Throughout eight years of clipboard hijacking activities, the threat actors successfully stole at least 12.1 million rubles, equivalent to approximately $150,000 in cryptocurrency. Notably, a substantial portion of these stolen digital assets remained untouched in the attackers’ wallets.
Due to cryptocurrency market appreciation, the value of these dormant holdings surged to approximately $1.5 million at their highest point in January 2025.
This operation demonstrates how relatively unsophisticated techniquesāmerely substituting a copied addressācan evade detection for extended periods.
Cryptocurrency users can safeguard themselves by implementing a simple verification practice: always compare the first and last characters of a wallet address immediately after pasting, before authorizing any transaction.
According to CrowdStrike, the cybercriminals operating Sality have permanently lost their ability to maintain communication with infected systems following this disruption campaign.





