
{"id":221893,"date":"2026-09-02T13:50:55","date_gmt":"2026-09-02T13:50:55","guid":{"rendered":"https:\/\/mycryptomania.com\/?p=221893"},"modified":"2026-09-02T13:50:55","modified_gmt":"2026-09-02T13:50:55","slug":"sality-takedown-isolates-15000-machines-used-in-crypto-theft","status":"publish","type":"post","link":"https:\/\/mycryptomania.com\/?p=221893","title":{"rendered":"Sality Takedown Isolates 15,000 Machines Used in Crypto Theft"},"content":{"rendered":"<p>CrowdStrike and the U.S. Department of Justice disrupted the Sality botnet, isolating more than 15,000 infected machines that had been used to distribute malicious payloads. Active since 2003, Sality spent the past eight years primarily delivering EggJagger, a tool that monitored copied cryptocurrency wallet addresses and replaced them with addresses controlled by its operator.<\/p>\n<p>The <a class=\"general-link\" href=\"https:\/\/x.com\/FBI\" target=\"_blank\" rel=\"noopener\">operation<\/a> targeted a damaging weakness in cryptocurrency payment workflows. When malware changes an address before a payment is completed, funds can be redirected to a different recipient. CrowdStrike estimates that EggJagger alone was responsible for at least 12.1 million rubles, or roughly $150,000, in stolen cryptocurrency.<\/p>\n<p>Today the <a href=\"https:\/\/x.com\/FBI?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@FBI<\/a>, <a href=\"https:\/\/x.com\/TheJusticeDept?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@TheJusticeDept<\/a>, and the Defense Criminal Investigative Service (DCIS) announced a multinational operation with actions in the United States and Europe to disrupt the botnet known as Sality.<\/p>\n<p>Since 2003, the Sality botnet has installed malware on compromised\u2026 <a href=\"https:\/\/t.co\/HNIY3oCGYr\" target=\"_blank\" rel=\"noopener\">pic.twitter.com\/HNIY3oCGYr<\/a><\/p>\n<p>\u2014 FBI Cyber Division (@FBICyberDiv) <a href=\"https:\/\/x.com\/FBICyberDiv\/status\/2094908431710732411?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">September 1, 2026<\/a><\/p>\n\n<p>Sality was first observed in 2003 and evolved into a peer-to-peer botnet. Rather than relying on a central command-and-control server, infected machines communicated directly with one another. The malware also spreads by attaching itself to executable files shared through network shares, removable drives, and file sharing.<\/p>\n<p>According to CrowdStrike, Sality\u2019s technical role was to deploy additional payloads to infected machines. EggJagger became its primary payload over the past eight years.<\/p>\n<p>The clipjacking tool monitored a victim\u2019s clipboard for <a class=\"general-link\" href=\"https:\/\/99bitcoins.com\/\" target=\"_blank\" rel=\"noopener\">cryptocurrency<\/a> wallet addresses and silently replaced them with an address controlled by the operator. A person copying a Bitcoin or Ethereum address to make a payment could therefore have funds redirected away from the intended recipient.<\/p>\n<p>This mechanism differs from an exchange breach or a smart-contract exploit. It involved the device and clipboard used in the process of preparing a cryptocurrency payment, rather than an attack on the blockchain itself.<\/p>\n<p><a href=\"https:\/\/99bitcoins.com\/visit\/bybit-airdrop-campaign\" class=\"sc-button sc-button-green sc-button-medium\" target=\"_blank\" rel=\"noopener\"><span>Trade XRP on ByBit and Join 99Bitcoin\u2019s Exclusive $1000 USDT Airdrop Campaign<\/span><\/a><\/p>\n<h2>What the Takedown Proves, and What It Does Not<\/h2>\n<p>CrowdStrike\u2019s Counter Adversary Operations team used Sality\u2019s peer-to-peer design against the botnet. The operation manipulated peer lists by removing legitimate peers and inserting CrowdStrike-controlled sinkholes. This isolated infected machines from the operator\u2019s control and prevented the botnet from receiving new tasking.<\/p>\n<p>The U.S. Department of Justice, FBI, and Defense Criminal Investigative Service took action against Sality-linked infrastructure in the United States. Law-enforcement partners in Bulgaria, Hungary, and Romania supported related action in Europe. The Shadowserver Foundation is working with internet providers to notify victims.<\/p>\n<p>Agents at the FBI\u2019s cyber division headquarters monitor global data streams in real-time.<\/p>\n<p>CrowdStrike tracks the operator as SALTY SPIDER. The firm said the stolen cryptocurrency was largely left unspent, with the portfolio reaching a peak value of about 147 million rubles in January 2025, nominally around $1.35 million.<\/p>\n<p>Disrupting the operator\u2019s control channel does not remove malware from compromised systems. CrowdStrike said that malware already present on infected machines remains active until it is removed, meaning affected systems still require remediation.<\/p>\n<p><strong>EXPLORE:\u00a0<a class=\"general-link\" href=\"https:\/\/99bitcoins.com\/cryptocurrency\/next-1000x-crypto\/\" target=\"_blank\" rel=\"noopener\">Best Crypto Presales With Asymmetric Upside in the Current Market<\/a><\/strong><\/p>\n<h2>Why the Theft Matters for Crypto Users<\/h2>\n<p>The confirmed EggJagger theft total is limited to one payload family, but the mechanism shows how malware can interfere with a routine payment workflow. A copied address can originate from a legitimate source, while the clipboard content is altered on an infected device before a transaction is completed.<\/p>\n<p>The more than 15,000 machines isolated during the operation illustrate the scale of the infrastructure CrowdStrike addressed. The case centers on clipboard substitution: malware monitored cryptocurrency wallet addresses and replaced them with addresses controlled by the operator, redirecting payments made from infected computers.<\/p>\n<h2>Bitcoin and the Sality Disruption<\/h2>\n<p>Bitcoin\u2019s market context and the Sality operation are separate issues. The botnet used cryptocurrency addresses as part of its theft scheme, but the evidence surrounding the disruption does not establish a connection between the operation and Bitcoin\u2019s market direction.<\/p>\n<p><span><\/span><\/p>\n<div class=\"chart crypto-chart-instance\">\n<div class=\"chart__header\">\n<div class=\"chart__info\">\n<div class=\"chart__info-icon\">\n<div class=\"chart__info-name\"><\/div>\n<div class=\"chart__info-symbol\"><\/div>\n<\/div>\n<div class=\"chart__info-current\">\n<div class=\"chart__info-price\"><\/div>\n<div class=\"chart__info-change\"><\/div>\n<\/div>\n<div class=\"chart__info-extra\">\n<div class=\"chart__info-label\">Market Cap<\/div>\n<div class=\"chart__info-marketcap\"><\/div>\n<\/div>\n<\/div>\n<div class=\"chart__controls\">\n<div class=\"chart__controls-group\">\n\t\t\t\t<button class=\"chart__button chart__button--24h\">24h<\/button><br \/>\n\t\t\t\t<button class=\"chart__button chart__button--7d\">7d<\/button><br \/>\n\t\t\t\t<button class=\"chart__button chart__button--30d\">30d<\/button><br \/>\n\t\t\t\t<button class=\"chart__button chart__button--1y\">1y<\/button><br \/>\n\t\t\t\t<button class=\"chart__button chart__button--all-time\">All Time<\/button>\n\t\t\t<\/div>\n<\/div>\n<\/div>\n<div class=\"chart__container\"><\/div>\n<\/div>\n<p><\/p>\n<p>The takedown is instead a cybersecurity development involving the safety of payment workflows on compromised devices. Its immediate effect, according to CrowdStrike, was to isolate infected machines so that the operator could no longer communicate with them or issue new instructions.<\/p>\n<p>For cryptocurrency users, the central issue is not a change to the underlying blockchain. It is the risk that malware on a device can alter payment information during a transaction workflow. The continuing presence of malware on affected machines also means the disruption did not itself clean those systems.<\/p>\n<div class=\"nnbtc-crypto-review aligncenter\">\n<div class=\"nnbtc-crypto-review__text\">\n<h3 class=\"nnbtc-crypto-review__heading\">MEXC<\/h3>\n<\/div>\n<div class=\"nnbtc-crypto-review__rating\">\n<div class=\"nnbtc-crypto-review__rating-value\">4.7<\/div>\n<div class=\"nnbtc-crypto-review__rating-stars\"><span class=\"nnbtc-crypto-review__star nnbtc-crypto-review__star--full\"><\/span><span class=\"nnbtc-crypto-review__star nnbtc-crypto-review__star--full\"><\/span><span class=\"nnbtc-crypto-review__star nnbtc-crypto-review__star--full\"><\/span><span class=\"nnbtc-crypto-review__star nnbtc-crypto-review__star--full\"><\/span><span class=\"nnbtc-crypto-review__star nnbtc-crypto-review__star--half\"><\/span><\/div>\n<\/div>\n<div class=\"nnbtc-crypto-review__description\">MEXC is our favourite full-suite crypto exchange offering trading, staking, airdrops and more<\/div>\n<\/div>\n<p><a href=\"https:\/\/99bitcoins.com\/visit\/mexc\" class=\"sc-button sc-button-green sc-button-medium\" target=\"_blank\" rel=\"noopener\"><span>Visit MEXC<\/span><\/a><\/p>\n<p><strong>Follow\u00a0<a class=\"general-link\" href=\"https:\/\/twitter.com\/99bitcoins\" target=\"_blank\" rel=\"noopener\">99Bitcoins on X<\/a>\u00a0For the Latest Market Updates and\u00a0<a class=\"general-link\" href=\"https:\/\/www.youtube.com\/@99Bitcoins\" target=\"_blank\" rel=\"noopener\">Subscribe on YouTube<\/a>\u00a0For Daily Expert Market Analysis.<\/strong><\/p>\n<p>\u00a0<\/p>\n<p>The post <a href=\"https:\/\/99bitcoins.com\/news\/scams-theft\/sality-botnet-takedown-crypto\/\">Sality Takedown Isolates 15,000 Machines Used in Crypto Theft<\/a> appeared first on <a href=\"https:\/\/99bitcoins.com\/\">99Bitcoins<\/a>.<\/p>","protected":false},"excerpt":{"rendered":"<p>CrowdStrike and the U.S. Department of Justice disrupted the Sality botnet, isolating more than 15,000 infected machines that had been used to distribute malicious payloads. Active since 2003, Sality spent the past eight years primarily delivering EggJagger, a tool that monitored copied cryptocurrency wallet addresses and replaced them with addresses controlled by its operator. The [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":221894,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"class_list":["post-221893","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-discovery"],"_links":{"self":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/posts\/221893"}],"collection":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=221893"}],"version-history":[{"count":0,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/posts\/221893\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/media\/221894"}],"wp:attachment":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=221893"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=221893"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=221893"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}