TLDRFederal authorities partnered with CrowdStrike to eliminate Sality, a Russian botnet operational for more than 20 yearsCybercriminals deployed EggJagger, a clipjacking program that replaced cryptocurrency wallet addresses with fraudulent onesAttackers accumulated approximately $150,000 worth of Bitcoin and Ethereum through eight years of clipboard manipulationThe value of hoarded stolen cryptocurrency reached approximately $1.5 million during the January 2025 market surgeMore than 15,000 compromised computers were disconnected from the criminal network during a live demonstration in Las VegasCrowdStrike collaborated with United States federal investigators to dismantle Sality, a criminal botnet that operated for more than twenty years, dedicating its final eight years to systematically siphoning cryptocurrency from unsuspecting victims.DOJ JUST CUT DOWN A 20 YEAR BOTNET USED FOR CRYPTO THEFT!The Justice Department said a U.S., Bulgaria, Hungary and Romania operation disrupted Sality, malware first seen in 2003 that later turned infected PCs into a peer-to-peer botnet used for crypto theft and other attacks.… pic.twitter.com/AdwK8cTLEj— Crypto Banter (@crypto_banter) September 2, 2026The scheme functioned by monitoring clipboard activity on infected systems. Whenever a user copied a cryptocurrency wallet address to initiate a transaction, the malicious software substituted it with an attacker-controlled wallet. Victims would unknowingly paste the fraudulent address, authorize the transfer, and send their digital assets directly to the criminals without any indication of compromise.The Mechanics Behind the AttackEggJagger served as the primary weapon in this operation. According to CrowdStrike’s analysis, this clipjacking utility operated covertly on compromised systems, constantly surveilling clipboard data for cryptocurrency addresses.Cryptocurrency wallet addresses consist of lengthy alphanumeric sequences. Virtually nobody manually enters these addresses, creating a vulnerability that attackers ruthlessly exploited.The infection vector relied on shared network resources and removable storage devices. The malware embedded itself within legitimate applications and maintained persistence through self-replication mechanisms that required no user interaction.Unlike traditional botnets, Sality operated without centralized command infrastructure, complicating takedown efforts. The decentralized architecture enabled infected systems to communicate directly with one another, conducting status checks approximately every 40 minutes to maintain network connectivity.The Disruption StrategySecurity researchers at CrowdStrike identified a vulnerability within the peer-to-peer communication protocol. By substituting legitimate peer addresses with company-controlled infrastructure, investigators successfully isolated over 15,000 infected devices from the criminal network.The disruption occurred Monday during a real-time presentation at CrowdStrike’s Day Zero conference in Las Vegas.The Department of Justice publicly disclosed the operation Tuesday. The coordinated takedown involved international cooperation from Bulgarian, Hungarian, and Romanian authorities, alongside private sector contributions from CrowdStrike and the Shadowserver Foundation.According to DOJ statements, the infrastructure was based in Russia, with Sality actively distributing malware to compromised systems since 2003.Throughout eight years of clipboard hijacking activities, the criminal operators extracted at least 12.1 million rubles, equivalent to approximately $150,000 in digital currency. A substantial percentage of these illicit proceeds remained untouched in the attackers’ wallets.When cryptocurrency valuations surged, the worth of these dormant holdings escalated to roughly $1.5 million during their January 2025 zenith.This takedown illustrates how surprisingly simple techniques, like address substitution, can evade detection for extended periods.Cryptocurrency users can safeguard their assets by verifying the initial and final characters of wallet addresses immediately after pasting, before authorizing any transaction.According to CrowdStrike’s assessment, the operators behind Sality no longer possess the capability to interact with infected devices following the successful disruption campaign.The post Russian Crypto-Stealing Botnet Sality Shut Down After Two-Decade Run appeared first on Blockonomi.