CrowdStrike and U.S. authorities have taken down Sality, a Russia-based botnet that spent years stealing cryptocurrency by secretly changing wallet addresses copied by users.
Sality has existed since 2003, but its most recent campaign focused on cryptocurrency theft. Over approximately eight years, the malware monitored infected computers for Bitcoin and Ethereum addresses and replaced them with addresses controlled by the attackers. More than 15,000 compromised machines have now been isolated from the network.
The scheme exploited a common habit among crypto users. Wallet addresses are typically long combinations of letters and numbers, making copy-and-paste the easiest way to enter them when sending funds.
CrowdStrike identified the malware’s main crypto-stealing component as “EggJagger.” It operated in the background, monitoring a computer’s clipboard for strings that looked like Bitcoin or Ethereum wallet addresses. When it detected one, the malware substituted the legitimate destination with an attacker-controlled address.
Users could therefore paste the altered address into their wallet and complete a transfer without realizing anything had changed. Once the transaction was confirmed, the funds could generally not be recovered. Checking the first and last few characters of a wallet address after pasting it is one way users can help spot such substitutions.
According to CrowdStrike, the attackers stole at least 12.1 million rubles, worth around $150,000, during the campaign. However, much of the cryptocurrency remained untouched. As crypto prices increased, the value of those dormant assets reportedly reached approximately $1.35 million by early 2025.
The relatively small amount stolen does not diminish the significance of the campaign. Sality demonstrates how a basic malware technique can remain profitable when it targets a routine behavior used by millions of cryptocurrency holders.
The botnet was also built to avoid relying on a single central server. Instead, infected computers communicated directly with one another and periodically checked whether their known network peers were still active.
Sality could spread through software shared via network drives and USB devices, allowing infected systems to help propagate the malware with limited involvement from its operators.
The network also lacked a strong authentication mechanism. Any machine that responded in the expected manner could be accepted as a legitimate participant in the botnet.
CrowdStrike exploited that weakness during the takedown by redirecting legitimate peer addresses to servers under its control. The maneuver disconnected more than 15,000 infected systems from Sality’s network.
Authorities said the disruption took place Monday during a live demonstration at CrowdStrike’s Day Zero summit in Las Vegas.
U.S. officials identified the operation as Russia-based, marking a major disruption to a botnet that had been active for more than two decades and had spent years targeting cryptocurrency transactions.





