Doctorcrypto About RSS Subscribe
Doctorcrypto
Home › Latest › Sality Botnet Dismantled After Eight Years of Stealing Bitcoin and Ethereum
Latest

Sality Botnet Dismantled After Eight Years of Stealing Bitcoin and Ethereum

By Priya Chen · · 1 min read

A long-running malware operation that quietly siphoned cryptocurrency from thousands of computers for the better part of a decade has finally been shut down, according to researchers and law enforcement officials. Security firm CrowdStrike, working alongside the U.S. Department of Justice, isolated more than 15,000 infected machines in a coordinated takedown that reached across four countries.

## An Eight-Year Campaign The Sality botnet had operated in the shadows for roughly eight years, hijacking machines to steal Bitcoin and Ethereum from unsuspecting victims. Rather than targeting a single vulnerability, the operation relied on a sprawling network of compromised computers that fed stolen funds back to its operators over an extended period.

The scale of the effort helped it stay under the radar. By spreading across thousands of devices and jurisdictions, the botnet avoided the kind of concentrated activity that typically triggers alarms and rapid intervention.

An operation that lurked for eight years was undone in a single coordinated strike.

## The Takedown CrowdStrike and the DOJ managed to isolate and neutralize more than 15,000 infected machines during the operation. The action spanned four countries, reflecting the international footprint that has become common in modern cybercrime cases.

Cryptocurrency-focused malware has grown into a persistent threat as digital assets have gained value, with attackers increasingly turning to botnets to automate theft at scale. Coordinated efforts between private security firms and government agencies have become a key line of defense.

  • The Sality botnet operated for roughly eight years.
  • More than 15,000 infected machines were isolated.
  • The takedown involved CrowdStrike and the DOJ across four countries.
  • The malware targeted Bitcoin and Ethereum holdings.

The dismantling underscores how cross-border collaboration remains essential to combating crypto-targeting malware, particularly operations designed to blend into the background for years at a time.

Was this useful?👍 Yes👎 No