23-year-old botnet Sality felled by CrowdStrike sinkhole op
The takedown isolated 15,000 infected machines, breaking a peer-to-peer network that stole at least $150,000 in crypto via clipboard hijacking.

CrowdStrike's Counter Adversary Operations team, with international law enforcement and the Shadowserver Foundation, disrupted the 23-year-old Sality botnet. The move isolates infected machines and blocks the operator's control, setting a new precedent for collaborative cyber takedowns.
For 23 years, Sality was the cockroach of the malware world - a peer-to-peer botnet that refused to die, evolving from a spam and DDoS engine into a cryptocurrency thief. On Monday, that resilience hit a wall: CrowdStrike, working with international law enforcement and the Shadowserver Foundation, executed a sinkhole operation that severed the operator's grip on more than 15,000 infected machines worldwide. The takedown didn't rely on a single dramatic server seizure; it poisoned the botnet's own communication system, turning its architecture against itself. The result is a working example of how modern cyber defense can dismantle infrastructure that has survived for two decades, and a reminder that even the oldest threats are still quietly siphoning real money from ordinary users' wallets.
The hook in this story isn't just the longevity - it's the payload. For the past eight years, Sality's primary weapon has been EggJagger, a clipboard monitor that silently swaps cryptocurrency wallet addresses. When a victim copies a bitcoin or ethereum address to make a payment, EggJagger replaces it with an attacker-controlled one, redirecting funds into criminal pockets. CrowdStrike estimates the operator stole at least $150,000 in cryptocurrency using this method alone. That number might seem modest next to headline-grabbing ransomware hauls, but it represents a pure, low-noise theft stream that has run for years, touching individuals and businesses who thought they were paying a vendor or a friend. The bots also delivered credential-theft tools, spam distribution, proxy services, and DDoS capability, making Sality a Swiss Army knife for cybercrime.
The takedown itself is a masterclass in asymmetric warfare.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Technology
Cyborg cockroaches can now carry cameras and inject medicine on command
A WIRED report shows electrodes, cameras, and injection devices turning live roaches into remote medics for disaster rescue.
Isar Aerospace's Spectrum reaches orbit on second flight, a European commercial first
The German startup's second-flight success lands days before Macron's Paris summit, giving Europe a homegrown launch option as SpaceX and Blue Origin bow out.
Tesla's wheel-less Cybercab rolls into China as sales stall
The EV maker will debut its autonomous robotaxi in Beijing and Shanghai mid-September, hoping its tech wow-factor reignites demand in its second-largest market.



