A Russia-based botnet that hijacked cryptocurrency payments by quietly editing clipboard contents has been taken apart by CrowdStrike and federal law enforcement, ending a theft operation that ran for at least eight years.
Sality, first observed in 2003, spent most of its two-decade life as a file-infecting virus. In its later years it carried a far more targeted payload: a tool CrowdStrike calls EggJagger, which sat on infected machines and watched the clipboard for cryptocurrency wallet addresses. When a user copied a bitcoin or ethereum address to make a payment, the malware replaced it with an address controlled by the attacker.
Wallet addresses are long strings nobody types by hand, so copy and paste is the standard method. That made the scheme cheap and nearly invisible. A victim pasting into their wallet and hitting send paid a criminal, with no warning and nothing to undo. The swap happened between the copy and the paste, so nothing on the screen ever looked wrong.
How the takedown worked
Sality survived so long because of its architecture rather than its payload. It operated as a peer-to-peer botnet with two independent networks, known as version 3 and version 4, that shared the same codebase. Every infected machine checked whether its peers were online roughly every 40 minutes, which let the operators reorganize after disruptions and survive repeated cleanup attempts over the years.
That peer list was also the weak point. Working with the Shadowserver Foundation and international police agencies, CrowdStrike poisoned the peer lists and redirected traffic into sinkhole servers under their own control. The operators lost the ability to communicate with infected machines, and more than 15,000 of them have been isolated from the criminal network. Researchers had tried similar approaches before, but this was the first operation to cut both peer-to-peer networks off at once.
“When a victim copies a Bitcoin or Ethereum address to make a payment, the funds are redirected,” CrowdStrike said in its write-up of the operation.
The direct haul was modest by modern crypto-crime standards. CrowdStrike estimates EggJagger stole at least 12.1 million rubles, about $150,000, over eight years, with the value of never-spent stolen assets peaking near $1.5 million in January 2025. Most of the stolen coins were never moved, likely because the attackers knew any on-chain activity left a trail that investigators could follow years later. The operators appear to have treated the payload as passive income from a botnet that also earned money in other ways.
Two decades of reinvention
Sality started life in 2003 as a polymorphic file infector, attaching itself to executable files and spreading through network shares and removable drives. Over the years it distributed ransomware, DDoS tools and other payloads, including an attack on a Ukrainian software forum one day after the full-scale invasion in 2022. Researchers describe it as one of the most persistent threats on the internet, notable for how hard it was to kill rather than for what it stole.
The crypto-theft payload arrived in the botnet’s later years, when clipboard hijacking had become one of the oldest and most reliable scams in the industry. The technique requires no exploit against the wallet itself. It attacks the human habit of trusting the clipboard, and Sality shows that method can be industrialized and left running for years without detection.
What users can do
Hardware wallets remain the most practical defense, since they display the full address on a separate screen and the malware swaps the string before it reaches the device. Wallet software that verifies addresses after pasting helps too. Security teams are advising anyone who may have used an infected machine to review past outgoing transfers on-chain, since misplaced payments can sometimes be traced to exchange deposit addresses.
Law enforcement agencies have not named arrests in connection with the disruption, and the operators themselves have not been publicly identified. The sinkhole operation remains active. CrowdStrike says the two networks have not reformed, though the company expects the operators to attempt a rebuild given how long the botnet has survived previous setbacks.

discussion