Security

CrowdStrike and Federal Authorities Dismantle Russian Botnet That Silently Hijacked Crypto Payments for Eight Years

3 min read
CrowdStrike and Federal Authorities Dismantle Russian Botnet That Silently Hijacked Crypto Payments for Eight Years

CrowdStrike has disrupted the Russia-based Sality botnet after more than two decades of operation. Working with U.S. law enforcement and European partners, the company isolated more than 15,000 infected machines worldwide, according to a blog post published Sept. 1.

For the past eight years the botnet ran one primary payload: EggJagger. The clipboard-hijacking tool monitored copied Bitcoin and Ethereum wallet addresses, then silently swapped in addresses the operator controlled. Payments redirected without the sender ever knowing. CrowdStrike estimates the operator stole at least ₽12.1M rubles, roughly $150,000, via that payload alone.

A floor. Not a total. The estimate covers only the EggJagger family, and Sality ran other revenue-generating payloads alongside it.

The disruption was executed Aug. 31 using a technique CrowdStrike calls “peer-to-peer sinkholing”: legitimate super-peer entries in each infected machine’s peer list were invalidated and replaced with sinkhole entries, severing the connection to the operator’s command channel. Super peers went first. They were the network backbone. Machines behind firewalls or NAT were isolated passively afterward. Sality ran two independent peer-to-peer networks, versions 3 and 4. Same codebase, same operator, incompatible protocols and different cryptographic keys. Both stayed active until the operation.

Sality surfaced in 2003 as a file-infecting virus and evolved into a resilient peer-to-peer botnet. The Justice Department said the malware installed malicious software on compromised devices, enabling cryptocurrency theft and cyberattacks against victims in the U.S. and abroad. Most owners of infected computers never knew their machines had been conscripted.

The U.S. effort was led by the FBI and the Defense Department’s Defense Criminal Investigative Service. Sality-linked domains hosted in the United States were seized, according to a statement from the U.S. Attorney’s Office for the Central District of California. Law-enforcement partners in Bulgaria, Hungary, and Romania moved against additional Sality-linked domains in Europe. The Shadowserver Foundation is now coordinating with internet service providers and computer security incident response teams to find remaining infections and notify victims.

“This successful effort to take down the Sality botnet shows that by working together the public and private sectors can be a powerful force for good,” First Assistant U.S. Attorney Bill Essayli said in the statement.

Patrick Grandy, assistant director in charge of the FBI’s Los Angeles field office, said the collaboration “only enhances the FBI’s cyber security capabilities and our efforts to neutralize the threat posed by the Sality botnet.” Kenneth DeChellis, the special agent in charge of DCIS’s cyber field office, called protecting the Defense Department’s information network from threats like Sality “a top priority.”

CrowdStrike attributed the low dollar figure to the clipboard-swap method itself. The attack works only when a victim copies a wallet address at the exact moment a transaction is being prepared. Narrow window. It caps the volume of diverted funds. The operator’s never-spent holdings peaked at roughly ₽147M in January 2025, the company said.

Three DDoS campaigns stood out over Sality’s lifespan, per CrowdStrike: the Arabic financial forum forex2030.com in April 2016; the Ukrainian forum kharkovforum.com on Feb. 25, 2022, the day after Russia’s full-scale invasion of Ukraine; and Russian crypto exchange AvanChange in September 2023.

What remains unknown is substantial. Neither CrowdStrike nor the Justice Department named the operator. No arrest or indictment has been disclosed. Total cryptocurrency diverted across all payloads is unquantified. This is an infrastructure-level disruption, machines pulled from the botnet. Not a prosecution. Assistant U.S. Attorney Lauren Restrepo of the National Security Division led the U.S. effort, the Justice Department said.

“To the Sality operator and criminals like them: operating for decades without consequence does not mean operating without risk,” CrowdStrike wrote. “The calculus has changed.”

Avatar of Mara Velasquez

Mara Velasquez

Mara Velasquez covers markets and DeFi for NFT Signals, reporting on price action, liquidity and the listed companies with crypto on their balance sheets. She also tracks exploits and stolen-funds recovery.