Sality Botnet Taken Down: 8 Years of Bitcoin and Ethereum Clipjacking Halted
DOJ and CrowdStrike crippled the Sality botnet, isolating 15,000 PCs and ending eight years of Bitcoin/Ethereum clipjacking. The real weak spot wasn’t crypto—it was the clipboard.

Because Bitcoin
September 2, 2026
For nearly a decade, Sality didn’t beat cryptography—it beat user behavior. The botnet’s go-to payload, EggJagger, quietly watched clipboards on infected machines and swapped in the attacker’s wallet address whenever a victim copied a Bitcoin or Ethereum destination. No exploit, no key theft—just a small change at the last step of a payment flow that many people rush through.
On Tuesday, the Justice Department and CrowdStrike said they disrupted Sality, a peer-to-peer malware network that’s existed since 2003 and spent its last eight years siphoning crypto via clipjacking. CrowdStrike estimates the operator took at least 12.1 million rubles—about $150,000—through EggJagger alone. The more telling detail: the bulk of those coins sat unspent, with the stash peaking around 147 million rubles in January 2025, a nominal $1.35 million—roughly the purchasing power of $4 million in a major Western city. Patience, not velocity, was the strategy.
The takedown hinged on Sality’s decentralization. There was no central server to seize; infected nodes spoke directly to each other and spread by attaching themselves to executables moved over network shares and removable drives. Critically, Sality’s peer admission was permissive—bots accepted any machine that completed the handshake correctly. CrowdStrike’s Counter Adversary Operations team used that trust model against it, inserting sinkholes and pruning genuine peers from address lists. More than 15,000 infected machines were isolated worldwide.
Law enforcement synchronized the cutover. In the U.S., the Justice Department, FBI, and Defense Criminal Investigative Service seized Sality-linked domains, while police in Bulgaria, Hungary, and Romania took down related infrastructure in Europe. The Shadowserver Foundation is coordinating with ISPs to notify victims. Systems now beacon to CrowdStrike-controlled sinkholes, but any malware already resident on those machines remains until it’s actively removed; detection rules and network indicators have been published to guide clean-up.
Before clipjacking became the cash cow, Sality rented itself out for credentials theft, spam, proxy services, and denial-of-service jobs. The operator—tracked by CrowdStrike as SALTY SPIDER—also showed occasional spur-of-the-moment aggression. In September 2023, a DDoS payload, compiled just seconds before upload, struck AvanChange, a Russian crypto exchange—an episode CrowdStrike reads as a grievance-driven hit. Exchanges like it likely served as off-ramps to convert stolen coins into cash.
What actually made Sality lucrative wasn’t some novel evasion—it was the invisible gap between intent and execution in crypto payments. Alphanumeric wallet strings are long, visually noisy, and similar enough that many people rely on copying and matching only the first and last few characters. That habit is a gift to clipjackers. Address formats do include checksums, but if the malware swaps in a valid destination controlled by the attacker, wallets will happily broadcast. QR codes help, yet they’re often bypassed on desktops. Address allowlists reduce risk, yet are underused. And while transaction previews exist, people frequently treat them as confirmations rather than verifications.
There’s a clear path to raising the bar: - Harden the last mile. Force explicit address confirmations with strong visual hashing or human-readable paynames, not just partial-character matches. - Protect the clipboard. OS-level “sensitive clipboard” modes for wallet addresses, with one-time transfer tokens or signed intents, would blunt passive swap attacks. - Default to safer flows. Push QR-first and allowlist-first UX in retail wallets and exchange withdrawals; deprioritize raw copy/paste. - Educate to reduce reflex. Encourage habit loops that include reading the destination in the wallet UI, not in the originating app, before hitting send.
From a business standpoint, clipjacking thrives because the unit economics are attractive: low engineering cost, steady trickle of value, minimal on-chain risk if funds sit dormant through market upswings. The ethical angle is equally plain: a small nudge at the payment edge can quietly reroute value at scale, and it often targets non-technical users who believe they did everything “right.”
Sality’s architecture also offers a lesson for defenders. Decentralized botnets aren’t invincible; their resilience can mask brittle assumptions—like indiscriminate peer acceptance—that open the door to sinkholing. Coordinated public–private operations can exploit those seams, as they did here across four countries.
Sality’s network is now cut off, but the behavior it monetized is still common. If the industry doesn’t redesign the last click, another clipjacker will. The code changes are straightforward; the habit changes will take longer.