Skip to content
The Executives BriefThe Executives BriefBeta

23-year-old botnet Sality felled by CrowdStrike sinkhole op

The takedown isolated 15,000 infected machines, breaking a peer-to-peer network that stole at least $150,000 in crypto via clipboard hijacking.

ByLama Al-RashidTechnology Correspondent, The Executives Brief
·3 min read
23-year-old botnet Sality felled by CrowdStrike sinkhole op
Executive summary

CrowdStrike's Counter Adversary Operations team, with international law enforcement and the Shadowserver Foundation, disrupted the 23-year-old Sality botnet. The move isolates infected machines and blocks the operator's control, setting a new precedent for collaborative cyber takedowns.

For 23 years, Sality was the cockroach of the malware world - a peer-to-peer botnet that refused to die, evolving from a spam and DDoS engine into a cryptocurrency thief. On Monday, that resilience hit a wall: CrowdStrike, working with international law enforcement and the Shadowserver Foundation, executed a sinkhole operation that severed the operator's grip on more than 15,000 infected machines worldwide. The takedown didn't rely on a single dramatic server seizure; it poisoned the botnet's own communication system, turning its architecture against itself. The result is a working example of how modern cyber defense can dismantle infrastructure that has survived for two decades, and a reminder that even the oldest threats are still quietly siphoning real money from ordinary users' wallets.

The hook in this story isn't just the longevity - it's the payload. For the past eight years, Sality's primary weapon has been EggJagger, a clipboard monitor that silently swaps cryptocurrency wallet addresses. When a victim copies a bitcoin or ethereum address to make a payment, EggJagger replaces it with an attacker-controlled one, redirecting funds into criminal pockets. CrowdStrike estimates the operator stole at least $150,000 in cryptocurrency using this method alone. That number might seem modest next to headline-grabbing ransomware hauls, but it represents a pure, low-noise theft stream that has run for years, touching individuals and businesses who thought they were paying a vendor or a friend. The bots also delivered credential-theft tools, spam distribution, proxy services, and DDoS capability, making Sality a Swiss Army knife for cybercrime.

The takedown itself is a masterclass in asymmetric warfare.

Executive ActionsLocked

This story's Key Insights and Take-aways are locked.

Create a free account to unlock Executive Actions for one credit.

Register to Unlock

Always free for Executives Club members. Join the Club

More in Technology