Crypto: Sality network falls after eight years of Bitcoin and Ethereum theft
Summarize this article with:

The dismantling of Sality puts an end to a long cryptocurrency embezzlement operation. This botnet, active since 2003, has devoted the last eight years to stealing bitcoins and Ethers. Its modus operandi was based on a simple technique: modifying the wallet addresses copied on the infected machines. CrowdStrike and the US Department of Justice coordinated the operation. More than 15,000 machines were isolated in several regions of the world after this global operation. The crypto phenomenon was at the heart of this activity.

Illustration of a global operation against the Sality botnet, showing a police officer confronting arrested cybercriminals, while a computer displays the logos of Bitcoin and Ethereum, symbolizing the diversion of crypto payments.

In brief

  • Sality, a botnet active since 2003, was dismantled after eight years of hijacking Bitcoin and Ethereum.
  • EggJagger replaced wallet addresses copied by victims in order to divert their payments.
  • CrowdStrike estimates EggJagger-related losses at least 12.1 million rubles, or about $150,000.
  • The operation isolated more than 15,000 infected machines around the world.

A botnet that hijacks Bitcoin and Ethereum payments

Sality functioned as a network of infected machines that communicated directly with each other. For eight years, its main tool, EggJagger, monitored the clipboards of compromised computers. When a victim copied a Bitcoin or Ethereum address, the program replaced it with that of the operator. The payment then went to another address.

This method did not directly modify a transaction on a blockchain. The botnet intervened before sending, when the user was preparing their payment. CrowdStrike estimated that EggJagger caused at least 12.1 million rubles in losses. This sum represents approximately $150,000 in the crypto sector.

Before EggJagger, Sality already operated several sources of criminal income. The network was used in particular for credential theft, spam, proxy services and denial of service attacks. Its crypto activity marked an evolution of its model. The operator then kept a large part of the stolen assets.

Your first cryptos with Coinbase
This link uses an affiliate program

An architecture that complicated dismantling

Sality has resisted thanks to an architecture without a central usable server. The infected machines exchanged information directly, which complicated the intervention. The malware spread via executable files on network shares and removable drives. He could thus regenerate automatically.

The botnet accepted accessible machines that correctly responded to its authentication mechanism. However, it did not verify the identity of new users. CrowdStrike exploited this weakness to remove legitimate peers from the address lists of infected machines. It added its own blockpoints to isolate more than 15,000 computers.

The operation mobilized several authorities. According to the press release of the Department of Justice, the FBI and the Defense Criminal Investigative Service seized domain names associated with Sality in the United States. In Europe, Bulgarian, Hungarian and Romanian police have dismantled other infrastructure. The Shadowserver Foundation works with ISPs to inform victims in the crypto ecosystem.

Stolen cryptos still largely intact

The Sality botnet left behind a wallet containing a large portion of the stolen cryptocurrencies. CrowdStrike valued these funds at approximately 147 million rubles in January 2025. This value represented approximately $1.35 million. This sum also corresponded to a purchasing power of four million dollars in a Western capital.

SALTY SPIDER also used its network against certain targets. In September 2023, a denial of service attack notably targeted AvanChangea Russian cryptocurrency exchange. CrowdStrike says the malicious code was compiled seconds before it went live. She interprets this delay as an impulsive reaction to a personal grievance.

After the intervention, infected machines now transmit their information to test servers controlled by CrowdStrike. The company has published detection rules and network indicators. Already installed malware remains active until removed. The botnet therefore does not automatically disappear from devices after dismantling.

In the short term, the intervention alters Sality’s communications and limits her control over the machines. The retained funds remain a central element of the crypto scam case. Infection tracking and software removal will now determine the scope of the operation. The Sality botnet thus enters a new phase, marked by the isolation of its machines and the monitoring of its traces.

Maximize your Tremplin.io experience with our ‘Read to Earn’ program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.

Similar Posts