Skip to main content
AVOID.NET

Sality Botnet / EggJagger Crypto Clipboard Stealer

avoid.net/sality-botnet-eggjagger-crypto-clipboard-stealer2/100·93% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·4KnGzT…eQqm

Summary

Sality is a long-running malware family and peer-to-peer botnet first discovered in 2003, attributed by CrowdStrike to a Russia-based eCrime group tracked as SALTY SPIDER. For at least the eight years preceding its disruption, the botnet's primary payload was EggJagger, a clipboard-hijacking tool that silently replaced cryptocurrency wallet addresses on infected machines with attacker-controlled addresses. On August 31, 2026, a coordinated operation involving the U.S. Department of Justice, FBI, international law enforcement from Bulgaria, Hungary, and Romania, CrowdStrike, and the Shadowserver Foundation severed more than 15,000 infected machines from the botnet's infrastructure via a peer-to-peer sinkholing operation, though no arrests were announced and malware already installed on compromised machines remained active pending manual remediation.

Connected Entities

1 entities
Organizations
Sality Botnet / EggJagger Crypto Clipboard Stealer
Relationships
    Have evidence about Sality Botnet / EggJagger Crypto Clipboard Stealer?

    Timeline(11 events)

    1 January 2003

    Sality malware first identified as a polymorphic Windows executable file infector with centralized command-and-control, keylogging, and backdoor capabilities. Attributed to a Russia-based actor.

    CrowdStrike / Wikipedia

    1 January 2010

    Sality migrates to a peer-to-peer architecture, eliminating its central C2 server. Rootkit functions added around this period.

    Salty Spider Threat Actor Profile — Huntress

    1 April 2016

    Botnet tasked with a DDoS attack against forex2030.com.

    CrowdStrike — Inside the Sality Botnet Disruption Operation

    1 January 2017

    SALTY SPIDER reportedly ceases distribution of proxy and spambot payloads and pivots to cryptocurrency theft as primary monetization strategy.

    Salty Spider Threat Actor Profile — Huntress

    1 January 2018

    EggJagger clipboard-hijacking payload begins deployment across the Sality botnet, targeting Bitcoin and Ethereum wallet addresses copied to victims' clipboards.

    CrowdStrike — Inside the Sality Botnet Disruption Operation

    25 February 2022

    Botnet tasked with an HTTP flood DDoS attack against kharkovforum.com, a Ukrainian web forum hosting discussion of Russia's offensive on Kharkiv, one day after Russia's full-scale invasion of Ukraine began.

    The Hacker News — Authorities Turn Sality's P2P Network Against Itself

    1 September 2023

    Botnet operator tasks a DDoS payload against AvanChange, a Russian cryptocurrency exchange. CrowdStrike noted the payload was compiled seconds before upload, suggesting a personal grievance rather than strategic planning.

    CrowdStrike — Inside the Sality Botnet Disruption Operation

    1 January 2025

    CrowdStrike estimates the operator's unspent stolen cryptocurrency portfolio peaks at approximately 147 million rubles ($1.35 million USD nominal value).

    Decrypt — Sality Botnet Dismantled After Eight Years of Stealing Bitcoin and Ethereum

    31 August 2026

    CrowdStrike's Counter Adversary Operations team, with the DOJ, FBI, Defense Criminal Investigative Service, and law enforcement from Bulgaria, Hungary, and Romania, executes a peer-to-peer sinkholing operation. More than 15,000 infected machines severed from the botnet. Sality-linked domains seized in the U.S. and Europe. No arrests announced.

    U.S. Department of Justice — Sality Malware Disrupted in International Cyber Takedown

    2 September 2026

    DOJ, Europol, and CrowdStrike publicly announce the Sality botnet disruption. CrowdStrike researcher Tillmann Werner describes the operation as the most complex botnet takedown the company had ever conducted.

    Europol — Global public-private operation disrupts Sality botnet active for two decades

    2 September 2026

    Security researchers note that EggJagger and other Sality components remain active on previously infected machines pending manual remediation. CrowdStrike publishes the sinkhole IP address (188.166.101.148) to assist with detection.

    CryptoSlate — Copy and paste crypto address attack remains active after major malware cleanup
    Provenance & Audit Trail

    Decision Log

    This investigation is cryptographically anchored to the Solana blockchain (1 event). 16 of 17 cited source URLs have an Internet Archive snapshot.

    model: claude-sonnet-4-6

    generated: 9/15/2026, 5:08:08 PM

    last updated: 9/16/2026, 12:12:21 AM

    avoid.net — verified advice for a post-truth world