An international operation executed on August 31 and carried out in a live demonstration that day at CrowdStrike's Day Zero conference in Las Vegas cut the operator off from Sality, a Windows peer-to-peer botnet first seen in 2003 that for about eight years delivered EggJagger, a clipboard hijacker swapping copied Bitcoin and Ethereum wallet addresses for attacker-controlled ones. CrowdStrike's Counter Adversary Operations team ran the technical disruption, isolating more than 15,000 infected machines across two still-active networks, versions 3 and 4, so the operator can no longer issue tasking or new payloads. The Justice Department, FBI, and Defense Criminal Investigative Service seized Sality-linked domains in the United States, while authorities in Bulgaria, Hungary, and Romania took down additional European domains; Europol said the infrastructure has been tied over two decades to more than 11 million unique IP addresses and once reached as many as one million infected machines at peak. CrowdStrike estimated EggJagger stole at least 12.1 million rubles, about $150,000, while never-spent holdings peaked near 147 million rubles, or $1.35 million, in January 2025, a zenith some accounts place near $1.5 million. The firm tracks the operator as SALTY SPIDER, assessed as likely based in Russia's Republic of Bashkortostan; no defendant was named and no arrest was announced, and isolation does not itself remove the malware from infected hosts.