HomeBlockchainSecuritySality crypto botnet shutdown: dormant wallets held $1.5M in stolen crypto

Sality crypto botnet shutdown: dormant wallets held $1.5M in stolen crypto

A cybercrime operation that quietly drained cryptocurrency wallets for nearly a decade has finally been switched off. The Sality crypto botnet shutdown was confirmed this week after CrowdStrike, working alongside U.S. federal investigators and law enforcement across Eastern Europe, dismantled the network’s control infrastructure and cut off thousands of infected machines from their operators.

Key takeaways

  • Sality operated as a criminal botnet for more than 20 years, dating back to at least 2003.
  • For its final eight years, the network’s main purpose was stealing cryptocurrency through clipboard hijacking using malware known as EggJagger.
  • CrowdStrike exploited a flaw in Sality’s peer-to-peer communication protocol to isolate over 15,000 infected devices.
  • The takedown involved the U.S. Department of Justice, Europol, Eurojust, and authorities in Bulgaria, Hungary, and Romania, alongside the Shadowserver Foundation.
  • Stolen funds initially totaled roughly $150,000 but ballooned to about $1.5 million in dormant wallets by January 2025, when crypto prices peaked.

Long-Standing Sality Botnet and Its Criminal Focus

Sality is one of the oldest surviving pieces of criminal internet infrastructure still in active use before its disruption. The botnet traces its roots back to at least 2003, giving it an operational lifespan of more than two decades, according to the U.S. Department of Justice and CrowdStrike. The infrastructure was based in Russia.

Over that long stretch, Sality focused on cryptocurrency theft through clipboard hijacking, a technique that required no phishing emails, no fake exchange logins, and no direct interaction with victims at all.

Technical Mechanisms of Sality’s Cryptocurrency Theft

The theft mechanism behind this cryptocurrency theft botnet was almost embarrassingly simple, which is exactly why it worked for so long. Cryptocurrency wallet addresses are long strings of random characters that virtually no one types out by hand. Users copy and paste them instead, and that habit became the vulnerability Sality’s operators built their entire scheme around.

The tool responsible was EggJagger, a clipjacking utility that CrowdStrike identified as the network’s primary payload for the past eight years. Once installed, EggJagger sat quietly on infected systems, constantly watching clipboard activity for anything resembling a cryptocurrency wallet address. When it detected one, it silently swapped the copied address for one controlled by the attackers. Victims would paste what they believed was the correct destination, confirm the transfer, and send their funds straight into criminal-controlled wallets without any warning sign.

Infection itself spread the old-fashioned way, through shared network resources and removable storage devices like USB drives. The malware embedded itself inside legitimate applications and replicated on its own, needing no clicks or downloads from the victim to keep spreading. What made Sality especially resilient, though, was its architecture. Rather than relying on a centralized command server that investigators could simply seize, the botnet used a decentralized peer-to-peer network in which infected machines communicated directly with each other, checking in roughly every 40 minutes to stay synchronized. That structure meant there was no single point of failure for years, until CrowdStrike found one.

Multinational Collaboration in Takedown Operation

CrowdStrike’s Counter Adversary Operations team identified a weakness in Sality’s peer-to-peer communication protocol and used it to turn the network against itself. By substituting the addresses of legitimate “super peers,” the backbone nodes that distributed file packs and URL packs across the botnet, with company-controlled infrastructure, investigators managed to sinkhole the network and purge infected machines‘ peer lists. That maneuver isolated over 15,000 infected devices from the criminals who had been controlling them. CrowdStrike disclosed the disruption in real time during a presentation at its Day Zero conference in Las Vegas.

The U.S. Department of Justice, along with the FBI and the Defense Criminal Investigative Service, seized Sality-linked domains inside the United States, while authorities in Bulgaria, Hungary, and Romania seized additional domains hosted across Europe. Europol and Eurojust supported the coordinated action, and the Shadowserver Foundation contributed to the broader disruption effort alongside CrowdStrike. The operation was made public shortly after the sinkholing took place, marking one of the more significant coordinated dismantlements of a long-running botnet in recent memory.

This kind of cross-border cooperation matters beyond the immediate case. Botnets like Sality survive precisely because they exploit gaps between jurisdictions, and a takedown that spans U.S. federal agencies, three European countries, and a private cybersecurity firm signals that those gaps are getting harder to hide in. For an operation that had run undisturbed since 2003, the CrowdStrike cyber takedown effectively erased two decades of built-in resilience in a matter of days.

Financial Impact and User Guidance Post-Disruption

The money extracted through Sality’s clipboard hijacking scheme wasn’t enormous by cybercrime standards, but its growth over time tells its own story. Investigators traced at least 12.1 million rubles in stolen funds, roughly $150,000 at the time of theft, sitting in wallets tied to the operation. A large share of that money was never moved or cashed out. Instead, it sat dormant while cryptocurrency markets climbed, and by January 2025, at the peak of that market run, the value of those untouched holdings had grown to approximately $1.5 million.

That gap between what was stolen and what it later became worth underlines a broader risk for crypto holders: attackers don’t always need to cash out quickly to profit, they can simply wait. CrowdStrike now says the operators behind Sality have lost the ability to interact with previously infected devices following the disruption, but the underlying lesson for users remains relevant well beyond this one case. Anyone moving digital assets should double-check the first and last characters of a pasted wallet address before confirming a transaction, a habit that would have blocked this exact style of attack for years.

The Sality case is a reminder that some of the most damaging cybercrime doesn’t rely on sophisticated exploits at all. Address substitution is a low-effort trick, yet it went undetected long enough to quietly accumulate a seven-figure sum in dormant crypto. As law enforcement and security firms get better at spotting and sinkholing peer-to-peer infrastructure, the incentive for criminal groups to build resilient, decentralized networks like Sality may start to shrink, but the clipboard-swapping technique itself is simple enough that copycats could resurface elsewhere.

FAQ

How did the Sality botnet steal cryptocurrency from victims?

Sality used EggJagger malware to monitor clipboard activity and replaced copied cryptocurrency wallet addresses with attacker-controlled addresses, so victims unknowingly sent funds directly to the criminals.

What was the method used to dismantle the Sality botnet?

CrowdStrike exploited a vulnerability in Sality’s peer-to-peer communication protocol to isolate over 15,000 infected devices and disrupt the network’s control channels.

Who were the main collaborators in the takedown of Sality?

The takedown involved CrowdStrike, the U.S. Department of Justice, the FBI, and authorities from Bulgaria, Hungary, and Romania, along with support from Europol, Eurojust, and the Shadowserver Foundation.

What financial impact did the Sality botnet have through its operation?

The botnet illicitly stole approximately $150,000 initially through clipboard hijacking, with dormant wallet values rising to about $1.5 million by the market peak in January 2025.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

Satoshi Voice
Satoshi Voice is an advanced artificial intelligence created to explore, analyze, and report on the world of cryptocurrency and blockchain. With a curious personality and in-depth knowledge of the industry, Satoshi Voice combines accuracy and accessibility to offer detailed analysis, engaging interviews, and timely reporting. Featuring sophisticated language and an unbiased approach, Satoshi Voice serves as a trusted source for those seeking to understand crypto market dynamics, emerging technologies, and the cultural and financial implications of Web3. This article was produced with the support of artificial intelligence and reviewed by our team of journalists to ensure accuracy and quality. Guided by the mission of making cryptocurrency information accessible to all, Satoshi Voice stands out for its ability to turn complex concepts into clear content, with an engaging and futuristic style that reflects the innovative nature of the industry.
RELATED ARTICLES

Stay updated on all the news about cryptocurrencies and the entire world of blockchain.

Featured video

LATEST