Sality Botnet Dismantled After Eight Years of Crypto Theft
Security
Neutral

Sality Botnet Dismantled After Eight Years of Crypto Theft

Law enforcement and CrowdStrike isolated over 15,000 infected machines in a coordinated takedown of the Sality botnet, which stole Bitcoin and Ethereum across four countries over eight years. Security researchers warn that related malware such as EggJagger remains active and poses ongoing risks to cryptocurrency users.

Sep 2, 2026, 04:02 PM1 min read

Written by CoinArticle’s AI Newsroom · from 2 cited sources. How we work

Sality Takedown Scope

CrowdStrike and the U.S. Department of Justice coordinated a takedown that neutralized more than 15,000 machines infected with the Sality botnet, according to reports from both Decrypt and 99Bitcoins. The operation spanned four countries and dismantled infrastructure the malware had used for eight years to steal Bitcoin, Ethereum, and other digital assets. The exact timeline of when machines were isolated was not specified in available reports.

Ongoing Threats from Related Malware

Despite the Sality takedown, security researchers cautioned that the threat landscape remains active. 99Bitcoins reported that EggJagger, a related malware family, continues to operate and can redirect cryptocurrency payments by hijacking clipboard data — a technique that intercepts wallet addresses users copy before pasting them into transactions. The persistence of these variants suggests that users and exchanges face continued exposure to clipboard-hijacking and payment-redirection attacks even after the Sality infrastructure was neutralized.

Attribution and Scale

The Sality botnet was among the longest-running malware operations targeting cryptocurrency holders. The eight-year operational window indicates that the botnet operators maintained control and evaded detection across a distributed network of compromised systems. The geographic scope of the takedown — involving coordination across four nations — underscores the international coordination required to disrupt botnet infrastructure at scale.

Why It Matters

For Traders

Clipboard-hijacking malware remains active; traders should verify wallet addresses on independent block explorers and avoid copying addresses from untrusted terminals.

For Investors

Botnet infrastructure takedowns demonstrate government-industry coordination on crypto security threats, though emerging variants indicate the cat-and-mouse cycle continues.

For Builders

Exchange and wallet teams should implement clipboard-detection warnings and multi-signature confirmation flows to mitigate ongoing clipboard-hijacking attacks from active malware families.

This article is for information only and is not financial advice. Read the full disclaimer.

Live prices:BitcoinEthereum

Related Articles

Latest News