BTC
ETH
HTX
SOL
BNB
View Market
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

Global over 15,000 devices isolated; Sality botnet dismantled after stealing at least $150,000 in crypto assets

2026-09-02 11:41

Odaily News: CrowdStrike, in coordination with the U.S. Department of Justice, announced the dismantling of the Sality peer-to-peer botnet, isolating over 15,000 infected devices worldwide. The network has been active since 2003, and over the past eight years has primarily deployed a clipboard hijacking tool known as EggJagger to steal funds from Bitcoin and ETH transfers. EggJagger monitors cryptocurrency wallet addresses copied by victims and replaces them with addresses controlled by the attackers, redirecting transfer funds to the attackers. CrowdStrike estimates that this tool alone has stolen at least $150,000 in crypto assets; since most of the funds were not moved, the value of the associated holdings rose to approximately $1.35 million in January 2025. The U.S. Department of Justice, FBI, and Defense Criminal Investigative Service have seized related domains within the U.S., while police in Bulgaria, Hungary, and Romania have also shut down infrastructure in Europe. Currently, infected devices have been redirected to traffic reception servers controlled by CrowdStrike, but the original malware on the devices remains active until manually removed.