Crowdstrike Holdings IncCrowdStrike helped disrupt the Sality botnet and its crypto-stealing EggJagger payload, showcasing its security capabilities.

On September 1, the U.S. Department of Justice announced that it, along with authorities in Bulgaria, Hungary, and Romania, and private firms CrowdStrike and the Shadowserver Foundation, had disrupted the botnet 'Sality' and its malware. The operation was carried out on August 31, severing more than 15,000 infected devices worldwide from the operators' control. Sality is a peer-to-peer botnet first identified in 2003, which has persisted for over two decades because it has no central server and infected devices communicate directly with each other. According to CrowdStrike, the primary payload in the last eight years has been 'EggJagger,' which monitors the clipboard and replaces copied cryptocurrency addresses with those of the operators. This attack is simple but effective, as many users rely on copy-and-paste due to the long strings of wallet addresses. CrowdStrike estimates that this payload alone has stolen at least 12.1 million rubles (about 2.178 million yen), with most of it remaining unused, and by January 2025, the amount had swelled to approximately 147 million rubles (about 264.6 million yen). The operator, known as 'SALTY SPIDER,' is believed to be based in the Republic of Bashkortostan in Russia, but no arrests have been made and their identity has not been disclosed. Although the financial damage is small compared to major hacking incidents, the threat of clipper-type malware is growing, and in June, Microsoft warned about similar malware spreading via USB. CrowdStrike warns that infections will persist until they are eradicated and suggests that sending small test transfers is a practical defense measure.
Crowdstrike Holdings IncCrowdStrike helped disrupt the Sality botnet and its crypto-stealing EggJagger payload, showcasing its security capabilities.
Microsoft CorporationShadowserver Foundation partnered in the operation that severed over 15,000 infected devices from the botnet's control.