23-year-old botnet Sality felled by CrowdStrike sinkhole op
The takedown isolated 15,000 infected machines, breaking a peer-to-peer network that stole at least $150,000 in crypto via clipboard hijacking.

CrowdStrike's Counter Adversary Operations team, with international law enforcement and the Shadowserver Foundation, disrupted the 23-year-old Sality botnet. The move isolates infected machines and blocks the operator's control, setting a new precedent for collaborative cyber takedowns.
For 23 years, Sality was the cockroach of the malware world - a peer-to-peer botnet that refused to die, evolving from a spam and DDoS engine into a cryptocurrency thief. On Monday, that resilience hit a wall: CrowdStrike, working with international law enforcement and the Shadowserver Foundation, executed a sinkhole operation that severed the operator's grip on more than 15,000 infected machines worldwide. The takedown didn't rely on a single dramatic server seizure; it poisoned the botnet's own communication system, turning its architecture against itself. The result is a working example of how modern cyber defense can dismantle infrastructure that has survived for two decades, and a reminder that even the oldest threats are still quietly siphoning real money from ordinary users' wallets.
The hook in this story isn't just the longevity - it's the payload. For the past eight years, Sality's primary weapon has been EggJagger, a clipboard monitor that silently swaps cryptocurrency wallet addresses. When a victim copies a bitcoin or ethereum address to make a payment, EggJagger replaces it with an attacker-controlled one, redirecting funds into criminal pockets. CrowdStrike estimates the operator stole at least $150,000 in cryptocurrency using this method alone. That number might seem modest next to headline-grabbing ransomware hauls, but it represents a pure, low-noise theft stream that has run for years, touching individuals and businesses who thought they were paying a vendor or a friend. The bots also delivered credential-theft tools, spam distribution, proxy services, and DDoS capability, making Sality a Swiss Army knife for cybercrime.
The takedown itself is a masterclass in asymmetric warfare.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Technology
BASF sues Apple over Face ID, dragging iPhone and iPad into Texas court
The world's largest chemical company claims dozens of Apple devices infringe its face authentication patents - and it chose a venue known for fast, plaintiff-friendly patent trials.
Google's Gemini 3.8 Flash targets agents, Cyber twin finds 13-year-old Chrome bug
Two new Flash models: one for agentic work, one for cybersecurity, with Flash Cyber already patching Chrome and finding a decade-old flaw.
Uber's UK robotaxi debut: 15 self-driving cars, safety drivers inside
The ride-hailing giant's first UK autonomous fleet is a cautious pilot; here's what it signals for the robotaxi race.


