Circuit boards surrounded by tangled wires in dim
Crypto

DOJ says international operation disrupted Sality botnet tied to EggJagger crypto theft

CrowdStrike estimated ~$150,000 stolen over eight years, while “never-spent” holdings peaked near $1.5 million in Jan. 2025.

By Emma Carter4 min read

The US Justice Department said it disrupted the Sality botnet in an international effort with Bulgarian, Hungarian, and Romanian officials plus CrowdStrike and the Shadowserver Foundation. CrowdStrike tied Sality operators to EggJagger clipboard-hijacking that it estimated stole about $150,000 in crypto, with “never-spent” stolen holdings peaking around $1.5 million in January 2025.

DOJ and Partners Say Sality Botnet Was Disrupted

The US Justice Department said on Sept. 2 that it disrupted the Sality botnet and malware ecosystem in an international operation involving officials in Bulgaria, Hungary, and Romania, alongside private-sector partners CrowdStrike and the Shadowserver Foundation.

The action targets a long-running malware family that US officials said has been installed on compromised devices since 2003 and has been used for both crypto theft and broader cyberattacks. CrowdStrike described the botnet as peer-to-peer, with about 15,000 infected computers checking whether systems were online every 40 minutes, a design choice that tends to trade simplicity for resilience because there is no single obvious command server to pull.

The most concrete outcome described so far is a loss of operator control rather than a claim of full eradication. CrowdStrike said the criminals behind Sality “lost the ability to communicate with infected machines” as a result of authorities’ disruption efforts, but the packet does not include details on arrests, indictments, infrastructure seizures, or whether any sinkholing or long-term remediation is in place to prevent reconstitution.

EggJagger Clipjacking: How Clipboard Swaps Reroute Crypto Transfers

CrowdStrike said Sality operators used EggJagger, a clipboard-monitoring “clipjacking” tool that watches for copied wallet addresses and swaps them out before the victim pastes. In CrowdStrike’s description, it is a “clipjacking tool that monitors the clipboard for cryptocurrency wallet addresses and silently replaces them with addresses controlled by the operator,” turning a normal copy-and-paste workflow into the point of compromise.

The mechanic is simple and nasty because it hits the exact moment many active traders and self-custody users rely on muscle memory: copying a deposit address from an exchange or a counterparty, then pasting it into a wallet or withdrawal form. “When a victim copies a Bitcoin or Ethereum address to make a payment, the funds are redirected,” CrowdStrike said.

That matters operationally because the victim’s screen can still look “normal” in the flow of a fast transfer, especially when the address is long, the UI truncates it, or the user only spot-checks the first and last few characters. Clipjacking does not need to break cryptography or touch the chain. It just needs to win the race between copy and paste.

What Traders Can and Can’t Infer From the $150K Stolen vs $1.5M Peak Figure

CrowdStrike estimated that at least 12.1 million rubles, about $150,000, in cryptocurrency was stolen over the previous eight years via EggJagger. In the same reporting, CrowdStrike said the value of the stolen “never-spent” digital assets peaked at about $1.5 million in January 2025.

The gap between those two figures is the part traders should not hand-wave away. A modest cumulative theft estimate can still translate into a much larger mark-to-market footprint if stolen balances sit unmoved through a bull cycle, and “never-spent” holdings by definition are the easiest subset for defenders to track because they remain in place.

At the same time, the packet leaves key valuation and attribution details unresolved. It does not specify which assets comprised the thefts, the timing of thefts inside the eight-year window, or how the “never-spent” wallets were attributed and priced to reach the roughly $1.5 million peak in January 2025.

The next confirmations that would change the practical read are procedural and technical. Follow-up disclosures from the Justice Department or partner agencies would clarify whether the disruption included arrests, charges, or infrastructure seizures beyond the stated communications impact. Additional technical reporting from CrowdStrike or the Shadowserver Foundation would also matter, particularly on how a peer-to-peer network of this size was disrupted and whether reinfection or reconstitution is already being observed. The most actionable near-term signal for desks is new victim advisories or indicator-of-compromise releases that let endpoint teams detect EggJagger-style clipboard behavior in the wild.

My Read: This Is a Reminder That Endpoint Hygiene Still Beats On-Chain Forensics

The filing-style language around this operation is being read as a takedown, but the threshold that matters is whether the disruption is durable. “Lost the ability to communicate with infected machines” is a meaningful degradation of control, yet it is not the same thing as removing malware from endpoints or proving the infrastructure cannot be rebuilt.

Clipjacking is also a reminder that a lot of crypto loss still happens before a transaction ever hits a block explorer, because the attacker is targeting the user’s workflow, not the protocol. If follow-on disclosures produce concrete indicators and show the peer-to-peer network is not re-forming, this shifts from a headline disruption into a repeatable playbook that actually reduces clipboard-hijacking losses in day-to-day transfers.

Sources