Mark RadarMARK RADAR
About
EN
Sign in

US-Led Operation Dismantles Sality Botnet After 23 Years

1 reports · First detected 2026-09-02 · Last active 2026-09-02

Sality emerged in 2003 as file-infecting malware and evolved into a resilient peer-to-peer botnet that distributed credential stealers, spam tools, proxy services and distributed denial-of-service payloads. For the past eight years, its main payload was EggJagger, a clipjacking tool that replaced Bitcoin and Ethereum addresses copied to infected devices’ clipboards, redirecting otherwise legitimate cryptocurrency payments to wallets controlled by the operator.

CrowdStrike carried out the disruption on Aug. 31, 2026, alongside the U.S. Department of Justice, FBI, Defense Criminal Investigative Service, Shadowserver Foundation and authorities in Bulgaria, Hungary and Romania. The operation seized Sality-linked domains and used sinkholes to isolate more than 15,000 infected machines; the Justice Department announced it on Sept. 1. CrowdStrike estimated EggJagger stole at least $150,000, while the untouched holdings reached about $1.35 million in value in January 2025.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)