Sality Botnet / EggJagger Crypto Clipboard Stealer
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·4KnGzT…eQqmSummary
Sality is a long-running malware family and peer-to-peer botnet first discovered in 2003, attributed by CrowdStrike to a Russia-based eCrime group tracked as SALTY SPIDER. For at least the eight years preceding its disruption, the botnet's primary payload was EggJagger, a clipboard-hijacking tool that silently replaced cryptocurrency wallet addresses on infected machines with attacker-controlled addresses. On August 31, 2026, a coordinated operation involving the U.S. Department of Justice, FBI, international law enforcement from Bulgaria, Hungary, and Romania, CrowdStrike, and the Shadowserver Foundation severed more than 15,000 infected machines from the botnet's infrastructure via a peer-to-peer sinkholing operation, though no arrests were announced and malware already installed on compromised machines remained active pending manual remediation.
Connected Entities
1 entitiesTimeline(11 events)
1 January 2003
Sality malware first identified as a polymorphic Windows executable file infector with centralized command-and-control, keylogging, and backdoor capabilities. Attributed to a Russia-based actor.
CrowdStrike / Wikipedia1 January 2010
Sality migrates to a peer-to-peer architecture, eliminating its central C2 server. Rootkit functions added around this period.
Salty Spider Threat Actor Profile — Huntress1 April 2016
Botnet tasked with a DDoS attack against forex2030.com.
CrowdStrike — Inside the Sality Botnet Disruption Operation1 January 2017
SALTY SPIDER reportedly ceases distribution of proxy and spambot payloads and pivots to cryptocurrency theft as primary monetization strategy.
Salty Spider Threat Actor Profile — Huntress1 January 2018
EggJagger clipboard-hijacking payload begins deployment across the Sality botnet, targeting Bitcoin and Ethereum wallet addresses copied to victims' clipboards.
CrowdStrike — Inside the Sality Botnet Disruption Operation25 February 2022
Botnet tasked with an HTTP flood DDoS attack against kharkovforum.com, a Ukrainian web forum hosting discussion of Russia's offensive on Kharkiv, one day after Russia's full-scale invasion of Ukraine began.
The Hacker News — Authorities Turn Sality's P2P Network Against Itself1 September 2023
Botnet operator tasks a DDoS payload against AvanChange, a Russian cryptocurrency exchange. CrowdStrike noted the payload was compiled seconds before upload, suggesting a personal grievance rather than strategic planning.
CrowdStrike — Inside the Sality Botnet Disruption Operation1 January 2025
CrowdStrike estimates the operator's unspent stolen cryptocurrency portfolio peaks at approximately 147 million rubles ($1.35 million USD nominal value).
Decrypt — Sality Botnet Dismantled After Eight Years of Stealing Bitcoin and Ethereum31 August 2026
CrowdStrike's Counter Adversary Operations team, with the DOJ, FBI, Defense Criminal Investigative Service, and law enforcement from Bulgaria, Hungary, and Romania, executes a peer-to-peer sinkholing operation. More than 15,000 infected machines severed from the botnet. Sality-linked domains seized in the U.S. and Europe. No arrests announced.
U.S. Department of Justice — Sality Malware Disrupted in International Cyber Takedown2 September 2026
DOJ, Europol, and CrowdStrike publicly announce the Sality botnet disruption. CrowdStrike researcher Tillmann Werner describes the operation as the most complex botnet takedown the company had ever conducted.
Europol — Global public-private operation disrupts Sality botnet active for two decades2 September 2026
Security researchers note that EggJagger and other Sality components remain active on previously infected machines pending manual remediation. CrowdStrike publishes the sinkhole IP address (188.166.101.148) to assist with detection.
CryptoSlate — Copy and paste crypto address attack remains active after major malware cleanupDecision Log
- hash: Eei95Qsc1E8H2mwQnWz3U8fACq93ZqkjWp9F12EVgEuG
This investigation is cryptographically anchored to the Solana blockchain (1 event). 16 of 17 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 9/15/2026, 5:08:08 PM
last updated: 9/16/2026, 12:12:21 AM
avoid.net — verified advice for a post-truth world