US, Europe Disrupt Sality Botnet Used to Steal Cryptocurrency

3 Min Read Tags:
  • Authorities in the United States, Bulgaria, Hungary and Romania disrupted the Sality P2P botnet on Aug. 31, 2026, targeting infrastructure used to spread malware, conduct cyberattacks and steal cryptocurrency.
  • The operation matters because more than 11 million unique IP addresses were associated with Sality during its existence, according to Europol.
  • CrowdStrike estimated that Sality’s EggJagger component stole at least $150,000 in cryptocurrency.

The U.S. Department of Justice reported that the international operation involved authorities in the United States, Bulgaria, Hungary and Romania, with support from Europol and Eurojust. CrowdStrike and the Shadowserver Foundation also participated.

U.S. and European law enforcement seized domains linked to Sality. CrowdStrike specialists also conducted a sinkhole operation designed to isolate infected devices from the botnet’s operators.

According to Europol, more than 11 million unique IP addresses were associated with Sality’s infrastructure during its existence. At its peak, the operator could control as many as 1 million infected devices simultaneously. At the time of the operation, the network could distribute malware to more than 15,000 machines worldwide.

How Sality operated

Sality emerged in 2003 and evolved from a file-infector virus into a decentralized peer-to-peer botnet. Instead of relying on a centralized command-and-control server, infected devices exchanged commands directly with one another. That structure allowed the infrastructure to remain operational when individual nodes were taken offline.

The botnet distributed credential-stealing tools, proxy utilities and malware used for distributed denial-of-service attacks. Over the past eight years, one of its core components was EggJagger, a clipper that monitored copied Bitcoin and Ethereum wallet addresses and replaced them with addresses controlled by the attacker.

According to a CrowdStrike estimate, the Sality operator stole at least $150,000 in cryptocurrency through EggJagger. CrowdStrike said the estimate covered only EggJagger and excluded other sources of revenue associated with the botnet.

Specialists disrupted the network by exploiting a feature of its architecture. They removed active Sality nodes from infected devices’ peer lists and replaced them with controlled sinkhole servers, preventing the operator from sending new commands and malicious files to the bots.

Shadowserver is working with internet service providers and cyber incident response teams to identify remaining infected devices and notify their owners.

CrowdStrike believes Sality has Russian roots. The company said it reached that assessment by tracking the network’s likely operator, the cybercriminal group it calls SALTY SPIDER.

Since the beginning of 2025, total damage from cybersecurity incidents involving cryptocurrency platforms has amounted to $3.63 billion.

Source: Incrypted

Anthropic Models 3 US Economic Scenarios Through 2030

Anthropic published a model outlining three scenarios for the U.S. economy through 2030, with its extreme scenario suggesting annual GDP growth could reach 15% alongside historically high unemployment.

7 Min Read
Robinhood CEO Says Companies Cannot Control Tokenization of Their Shares

In September 2026, Robinhood CEO Vlad Tenev said companies cannot prevent third-party products linked to their shares, defending 1:1 share-backed Stock Tokens after AMC CEO Adam Aron challenged their legality.

5 Min Read
Germany Will Change Crypto-Asset Tax Rules in 2027, Media Reports

Germany’s draft crypto tax reforms would from Jan. 1, 2027, tax profits on covered assets acquired after Dec. 31, 2026, regardless of holding period, while platforms would begin withholding tax…

5 Min Read
Vitalik Buterin Says Recursive STARKs Could Cut Ethereum Private, Post-Quantum Transaction Costs

On Sept. 9, Ethereum co-founder Vitalik Buterin explained EIP-8288, a proposal to aggregate STARK proofs and cryptographic signatures at the mempool level, potentially reducing costs without changing the EVM.

6 Min Read
Bybit Launches AI Assistant for Trading, Account Management

Bybit announced the launch of Bybit AI, a voice assistant that lets eligible users access trading, account management and customer support through one app chat interface after activating an isolated…

4 Min Read