Sality Botnet Takedown Isolates 15,000 Machines in Crypto Clipboard Theft
CrowdStrike and DOJ action against Sality highlights device-level risks to crypto payments via EggJagger malware.
CrowdStrike and the U.S. Department of Justice disrupted the Sality botnet and isolated more than 15,000 infected machines.
Sality had delivered the EggJagger payload for eight years. The tool monitored copied cryptocurrency wallet addresses on the clipboard and replaced them with addresses controlled by the operator.
Remaining unknowns
CrowdStrike estimates EggJagger alone stole at least 12.1 million rubles, roughly $150,000. The operator portfolio reached a peak of about 147 million rubles, or $1.35 million, in January 2025, with most funds unspent.
The malware remains on compromised devices and requires separate removal. Total losses across all payloads and years are not quantified beyond the EggJagger figure. No direct link to broader Bitcoin market movements has been established.