US-Led Operation Dismantles Sality Botnet After 23 Years
Sality emerged in 2003 as file-infecting malware and evolved into a resilient peer-to-peer botnet that distributed credential stealers, spam tools, proxy services and distributed denial-of-service payloads. For the past eight years, its main payload was EggJagger, a clipjacking tool that replaced Bitcoin and Ethereum addresses copied to infected devices’ clipboards, redirecting otherwise legitimate cryptocurrency payments to wallets controlled by the operator.
CrowdStrike carried out the disruption on Aug. 31, 2026, alongside the U.S. Department of Justice, FBI, Defense Criminal Investigative Service, Shadowserver Foundation and authorities in Bulgaria, Hungary and Romania. The operation seized Sality-linked domains and used sinkholes to isolate more than 15,000 infected machines; the Justice Department announced it on Sept. 1. CrowdStrike estimated EggJagger stole at least $150,000, while the untouched holdings reached about $1.35 million in value in January 2025.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →