CrowdStrike and federal law enforcement dismantled the Sality botnet, isolating more than 15,000 infected machines that had been quietly stealing cryptocurrency through address-replacement attacks for years.
The malware operated by monitoring clipboard data when users copied Bitcoin and Ethereum addresses, then replacing them with attacker-controlled wallets before a transaction was pasted. Victims believed they were sending funds to legitimate destinations while their crypto was diverted elsewhere. The operation involved the Department of Justice, FBI, and Defense Counterintelligence and Security Agency, along with law enforcement partners across Europe.

Sality itself has operated since the early 2000s as a peer-to-peer botnet, but the cryptocurrency-focused variant using clipboard replacement, known as EggJagger, ran for eight years within that longer operational window. Sality's infrastructure spanned two decades, but the specific crypto-stealing phase that prompted the joint takedown operated at scale for roughly a third of that time.

The malware spread through infected software downloads and malicious email attachments. Once installed, it established persistence on Windows machines and communicated with other infected nodes to receive updated instructions. The peer-to-peer architecture made it harder to take down through a single point of failure, requiring authorities to coordinate takedowns across multiple nodes and jurisdictions simultaneously.
CrowdStrike identified and tracked the malware's activity, providing intelligence to federal authorities. The company's endpoint detection tools flagged the clipboard-replacement behavior as anomalous, creating the forensic trail that led to the broader investigation. European law enforcement agencies contributed intelligence and coordinated actions in their own jurisdictions.
The takedown disrupted a criminal operation that ran openly within the malware ecosystem for years without major public exposure until the joint enforcement action. The scale of 15,000 machines represents a meaningful fraction of the Windows base during the active phase, though the actual number of victims who lost crypto remains undisclosed.
The operation required coordination across three federal agencies, multiple international partners, and private sector security firms. Dismantling a peer-to-peer botnet of that size demanded simultaneous action to prevent infected machines from reconnecting through backup nodes after initial disruptions, a complexity that explains the lengthy investigation window before public announcement.