Introduction
In a recent announcement, CrowdStrike, in partnership with the U.S. Justice Department, has successfully dismantled the notorious Sality botnet, which has been active since 2003. This malware has shifted its operations over the last eight years, primarily targeting cryptocurrency users by manipulating wallet addresses on compromised computers. The implications of this operation have been significant, particularly due to its association with a tool called EggJagger, designed to intercept and alter cryptocurrency transfer details.
Functionality of EggJagger
EggJagger’s function focuses on monitoring the clipboard for cryptocurrency addresses, subsequently replacing them with addresses owned by the attacker. Consequently, users intending to send Bitcoin or Ethereum to another party unwittingly redirect their funds to a stranger. CrowdStrike estimates that the botnet’s activities, especially through EggJagger, have raked in at least 12.1 million rubles (approximately $150,000).
Historical Context and Adaptability
Beyond facilitating cryptocurrency fraud, Sality was adaptable, initially earning its keep through credential theft, spam distribution, proxy operations, and delivering other forms of malware, including denial-of-service attacks. Interestingly, while the stolen cryptocurrency remained untouched, CrowdStrike suggests this choice was strategically beneficial. By January 2025, the reportedly never-spent cryptocurrency was valued at around 147 million rubles, equating to about $1.35 million, or close to the effective purchasing power of $4 million in certain Western cities.
Resilience and Dismantling Efforts
Sality’s resilience, allowing it to evade capture for two decades, derived from its decentralized architecture, which enabled infected devices to communicate directly with each other, eliminating the risk of a central server seizure. The malware propagated through executable files shared over network drives and removable media without stringent checks on devices joining the network.
CrowdStrike’s Counter Adversary Operations team took advantage of this framework, successfully replacing over 15,000 infected machines’ connections with their own monitoring systems, referred to as sinkholes. In collaboration with law enforcement agencies in the U.S. and across Europe, including Bulgaria, Hungary, and Romania, they executed seizures of Sality-associated domains, further disrupting its operations. Additionally, the Shadowserver Foundation is assisting internet service providers in notifying affected users.
Operator and Future Implications
The enigmatic operator behind this botnet, known as SALTY SPIDER, has at times directed the botnet against specific targets. Notably, in September 2023, they unleashed a denial-of-service attack on AvanChange, a Russian cryptocurrency exchange, suggesting perhaps a personal vendetta or a rapid response to an incident.
Now, compromised systems that previously reported to the botnet’s owner will instead signal to CrowdStrike’s controlled sinkholes. The company has made available detection protocols and indicators to aid in identifying infected machines, though they caution that existing malware on these devices will remain active unless manually eliminated by users themselves.