Newsroom
3 September, 2026 / News / AI / Tags: crowdstrike, sality, peer, malware, botnet

U.S. authorities and CrowdStrike isolate more than 15,000 machines used in a long-running scheme that swapped Bitcoin and Ethereum wallet addresses
U.S. law enforcement agencies and cybersecurity firm CrowdStrike have disrupted Sality, a peer-to-peer botnet active since 2003 that spent the past eight years primarily delivering malware designed to steal cryptocurrency by altering wallet addresses on victims’ computers.
The operation, announced this week, isolated more than 15,000 infected machines and cut the operator’s ability to issue new instructions. Partners in Bulgaria, Hungary and Romania supported related actions in Europe, while the Shadowserver Foundation is working with internet service providers to notify owners of compromised devices.
For the last eight years Sality’s main payload was a tool identified as EggJagger. The malware monitored the system clipboard for copied Bitcoin or Ethereum wallet addresses and silently replaced them with addresses controlled by the operator. Users who then pasted the altered address and confirmed a transaction sent funds to the attacker instead of the intended recipient.
CrowdStrike estimates that EggJagger alone accounted for at least 12.1 million Russian rubles, or roughly $150,000, in stolen cryptocurrency. Much of the stolen digital assets remained unspent. The value of those holdings later rose with market prices, reaching a peak of about 147 million rubles, or approximately $1.35 million, in January 2025.
The theft method targeted the everyday process of preparing a payment rather than exchanges or blockchain protocols. Once a transaction is confirmed on the network it generally cannot be reversed, leaving victims with limited recovery options.
Sality first appeared in 2003 and evolved into a resilient peer-to-peer network. Infected computers communicated directly with one another rather than relying on a single central command server. The malware also spread by attaching itself to executable files shared through network drives, removable media and other common channels.
Earlier in its history the botnet distributed a range of payloads, including tools for credential theft, spam, proxy services and denial-of-service attacks. In recent years it focused on delivering EggJagger. The operator occasionally used the network for other purposes, including a denial-of-service attack in 2023 against a Russian cryptocurrency exchange.
The same peer-to-peer design that helped Sality endure for more than two decades also provided the opening for the disruption. Infected machines accepted any peer that responded correctly to basic checks, without additional authentication. CrowdStrike’s Counter Adversary Operations team manipulated peer lists by removing legitimate connections and inserting its own sinkhole servers. As a result, more than 15,000 machines were isolated from the operator’s control.
The Justice Department, FBI and Defense Criminal Investigative Service seized Sality-linked domains in the United States. Authorities in Bulgaria, Hungary and Romania took parallel steps against related infrastructure in Europe. Europol and Eurojust provided support for the multinational effort.
CrowdStrike conducted the technical isolation of the peer-to-peer network during a live demonstration at its Day Zero summit in Las Vegas. The company has released detection rules and network indicators to help identify remaining infections.
Officials noted that disrupting the operator’s communication channel does not automatically remove malware already present on compromised systems. Those devices continue to require individual remediation.
The Shadowserver Foundation is coordinating with internet service providers and national computer security teams to identify affected machines and assist with cleanup.
From the operator’s perspective the infected machines effectively disappear from the network. Remaining bots now connect to CrowdStrike-controlled sinkholes rather than receiving further commands. Payload hosting locations were also taken offline to limit any residual ability to fetch new malware.
The case illustrates a persistent risk for cryptocurrency users: malware on an everyday device can alter payment details during the brief moment an address is copied and pasted. Verifying the full address after pasting remains a practical safeguard against this form of interference.









