{"investigation":{"slug":"sality-botnet-eggjagger-crypto-clipboard-stealer","entity_name":"Sality Botnet / EggJagger Crypto Clipboard Stealer","trust_score":2,"severity_base":null,"score_modifier":0,"confidence":0.93,"status":"published","content_type":"investigation","summary":"Sality is a long-running malware family and peer-to-peer botnet first discovered in 2003, attributed by CrowdStrike to a Russia-based eCrime group tracked as SALTY SPIDER. For at least the eight years preceding its disruption, the botnet's primary payload was EggJagger, a clipboard-hijacking tool that silently replaced cryptocurrency wallet addresses on infected machines with attacker-controlled addresses. On August 31, 2026, a coordinated operation involving the U.S. Department of Justice, FBI, international law enforcement from Bulgaria, Hungary, and Romania, CrowdStrike, and the Shadowserver Foundation severed more than 15,000 infected machines from the botnet's infrastructure via a peer-to-peer sinkholing operation, though no arrests were announced and malware already installed on compromised machines remained active pending manual remediation.","sections":[{"content":"Sality is a family of polymorphic file-infecting malware first identified in 2003, targeting Microsoft Windows executable files with .EXE and .SCR extensions. Security researchers and CrowdStrike attribute its origin to Russia. In its earliest form, Sality prepended polymorphic viral code to host executables and included backdoor and keylogging capabilities. At inception, the botnet operated on a centralized command-and-control (C2) model. By approximately 2010, SALTY SPIDER had migrated to a peer-to-peer (P2P) architecture, eliminating the single point of failure inherent in centralized botnets. Rootkit functions were added around the same time. Over more than two decades, more than 11 million unique IP addresses have been associated with the botnet's infrastructure, and the network at its peak infected up to one million devices simultaneously.","heading":"Background and Origin","sources":[{"url":"https://www.crowdstrike.com/en-us/blog/who-is-salty-spider/","name":"Salty Spider Adversary Profile — CrowdStrike","type":"research","credibility":2},{"url":"https://en.wikipedia.org/wiki/Sality","name":"Sality — Wikipedia","type":"other","credibility":2},{"url":"https://www.helpnetsecurity.com/2026/09/02/sality-botnet-disruption-crowdstrike-law-enforcement/","name":"Global sinkhole operation ends Sality botnet's 23-year run — Help Net Security","type":"news_article","credibility":2}],"severity":"critical"},{"content":"Commencing approximately 2018 and continuing until the August 2026 disruption, the botnet's primary distributed payload was EggJagger, a clipboard-hijacking tool described by CrowdStrike as a 'clipjacking' program. EggJagger monitors clipboard contents on infected Windows machines for strings resembling cryptocurrency wallet addresses — documented targets include Bitcoin (BTC) and Ethereum (ETH) addresses. When the malware detects such a string, it silently replaces it with a wallet address controlled by the botnet operator. A victim copying a legitimate recipient's address before sending a payment would unknowingly paste the attacker's address, redirecting the transaction. The substitution occurs without any visible prompt or warning, making it difficult for victims to detect without carefully comparing the pasted address character-by-character against the original. CrowdStrike estimates the operator collected at least 12.1 million Russian rubles (approximately $150,000 USD at time of conversion) in confirmed theft through EggJagger. The stolen holdings were largely not liquidated; CrowdStrike estimated the unrealized value of the unspent portfolio peaked at approximately 147 million rubles, equivalent to roughly $1.35 million USD at January 2025 exchange rates, or an estimated $4 million in Western purchasing-power terms.","heading":"EggJagger: Cryptocurrency Clipboard Hijacking","sources":[{"url":"https://www.crowdstrike.com/en-us/blog/inside-sality-botnet-disruption-operation/","name":"Peer Pressure: Inside the Sality Botnet Disruption Operation — CrowdStrike","type":"research","credibility":2},{"url":"https://decrypt.co/377156/sality-botnet-dismantled-after-eight-years-of-stealing-bitcoin-and-ethereum","name":"Sality Botnet Dismantled After Eight Years of Stealing Bitcoin and Ethereum — Decrypt","type":"news_article","credibility":2},{"url":"https://www.coindesk.com/tech/2026/09/02/crowdstrike-and-federal-authorities-dismantle-russian-malware-that-secretly-stole-crypto-for-8-years","name":"CrowdStrike and federal authorities dismantle Russian malware that secretly stole crypto for 8 years — CoinDesk","type":"news_article","credibility":2}],"severity":"critical"},{"content":"Sality's P2P architecture, adopted around 2010, made it exceptionally resilient compared to centralized botnets. Infected machines communicated directly with one another rather than through a central server, building a self-healing mesh that could route around node failures or domain seizures. CrowdStrike documented at least four distinct P2P protocol versions over the botnet's lifespan, with versions 3 and 4 active at the time of the 2026 disruption. The P2P protocol lacked cryptographic authentication: any machine that responded correctly to the P2P handshake was accepted as a legitimate peer. Super peers — publicly reachable nodes — formed the network backbone, relaying peer lists to machines behind NAT or firewalls. Every approximately 40 minutes, bots checked whether stored peers remained online, a maintenance cycle that researchers later exploited during the disruption. Beyond EggJagger, the botnet over its history distributed diverse payload families including credential theft tools, spam distribution modules, proxy services, and distributed denial-of-service (DDoS) agents. In 2017, SALTY SPIDER reportedly ceased distribution of traditional proxy and spambot payloads and shifted the botnet's primary monetization focus to cryptocurrency theft.","heading":"Botnet Architecture and Technical Evolution","sources":[{"url":"https://www.crowdstrike.com/en-us/blog/inside-sality-botnet-disruption-operation/","name":"Peer Pressure: Inside the Sality Botnet Disruption Operation — CrowdStrike","type":"research","credibility":2},{"url":"https://thehackernews.com/2026/09/authorities-turn-salitys-p2p-network.html","name":"Authorities Turn Sality's P2P Network Against Itself — The Hacker News","type":"news_article","credibility":2},{"url":"https://www.huntress.com/threat-library/threat-actors/salty-spider","name":"Salty Spider Threat Actor Profile — Huntress","type":"research","credibility":2}],"severity":"high"},{"content":"In addition to credential theft and clipboard hijacking, the botnet was used on documented occasions to conduct DDoS attacks. CrowdStrike attributed three specific DDoS tasking events to the operator: a campaign targeting forex2030.com in April 2016; an HTTP flood targeting kharkovforum.com, a Ukrainian web forum hosting discussion of Russia's invasion of Kharkiv, on approximately February 25, 2022 — one day after Russia launched its full-scale invasion of Ukraine; and a September 2023 attack on AvanChange, a Russian cryptocurrency exchange. CrowdStrike noted that the AvanChange payload was compiled seconds before upload to the distribution infrastructure, which the firm interpreted as suggesting an impulsive reaction to a personal grievance rather than a coordinated strategic campaign.","heading":"DDoS Campaigns and Other Malicious Activity","sources":[{"url":"https://www.crowdstrike.com/en-us/blog/inside-sality-botnet-disruption-operation/","name":"Peer Pressure: Inside the Sality Botnet Disruption Operation — CrowdStrike","type":"research","credibility":2},{"url":"https://threatlandscape.io/blog/sality-p2p-botnet-disruption-peer-list-sinkholing-ends-a-23-year-operation","name":"Sality Botnet Disruption and P2P Sinkhole Analysis — Threat Landscape Blog","type":"news_article","credibility":3}],"severity":"high"},{"content":"CrowdStrike attributes the Sality botnet to a financially motivated Russia-based eCrime group it tracks under the designation SALTY SPIDER. CrowdStrike assessed with medium-to-high confidence that the operator is based in the Republic of Bashkortostan, a federal subject of Russia near the Kazakhstan border. No individual has been publicly named or charged in connection with the botnet as of the September 2026 disruption announcement. The attribution remains an intelligence assessment rather than an adjudicated finding.","heading":"Threat Actor Attribution","sources":[{"url":"https://www.crowdstrike.com/en-us/blog/who-is-salty-spider/","name":"Who is SALTY SPIDER? — CrowdStrike","type":"research","credibility":2},{"url":"https://www.huntress.com/threat-library/threat-actors/salty-spider","name":"Salty Spider Threat Actor Profile — Huntress","type":"research","credibility":2},{"url":"https://malpedia.caad.fkie.fraunhofer.de/actor/salty_spider","name":"SALTY SPIDER — Malpedia","type":"research","credibility":2}],"severity":"high"},{"content":"On August 31, 2026, CrowdStrike's Counter Adversary Operations team, in coordination with the U.S. Department of Justice, the FBI, the Defense Criminal Investigative Service, and law enforcement authorities in Bulgaria, Hungary, and Romania — with Europol and Eurojust providing coordination support — executed a peer-to-peer sinkholing operation against the Sality botnet. The technique, also used in the 2014 GameOver Zeus and 2017 Kelihos disruptions, exploited Sality's lack of authentication in its P2P protocol. Sinkhole nodes were injected into infected machines' peer lists, replacing legitimate super peers. During bots' routine 40-minute maintenance cycles, they contacted the sinkhole nodes, received purged peer lists, and were permanently isolated from the operator's command infrastructure. U.S. authorities seized Sality-linked domains in the United States; Bulgarian, Hungarian, and Romanian authorities seized additional domains in their jurisdictions. The Shadowserver Foundation was engaged for victim notification. CrowdStrike researcher Tillmann Werner described the operation to Reuters as the most technically complex botnet takedown the company had ever conducted. The operation severed more than 15,000 infected machines from the botnet. No arrests were announced in connection with the takedown.","heading":"August 2026 Disruption Operation","sources":[{"url":"https://www.justice.gov/usao-cdca/pr/sality-malware-disrupted-international-cyber-takedown","name":"Sality Malware Disrupted in International Cyber Takedown — U.S. Department of Justice","type":"regulatory","credibility":1},{"url":"https://www.europol.europa.eu/media-press/newsroom/news/global-public-private-operation-disrupts-sality-botnet-active-for-two-decades","name":"Global public-private operation disrupts Sality botnet active for two decades — Europol","type":"regulatory","credibility":1},{"url":"https://therecord.media/sality-botnet-cyber-doj","name":"Sality, one of the longest-running botnets, finally gets disrupted — The Record (Recorded Future)","type":"news_article","credibility":1},{"url":"https://www.crowdstrike.com/en-us/blog/inside-sality-botnet-disruption-operation/","name":"Peer Pressure: Inside the Sality Botnet Disruption Operation — CrowdStrike","type":"research","credibility":2},{"url":"https://www.cybersecuritydive.com/news/doj-crowdstrike-botnet-sality-takedown/829512/","name":"Government, industry partner to shut down long-running Sality botnet — Cybersecurity Dive","type":"news_article","credibility":2}],"severity":"low"},{"content":"The August 2026 sinkholing operation severed infected machines from the botnet operator's command infrastructure, preventing the distribution of new payloads and removing the operator's ability to task infected systems. However, the operation did not remove malware already installed on compromised machines. EggJagger and other Sality components remain active on previously infected systems until manually remediated. CrowdStrike advised that administrators and users check network logs for communications to the sinkhole address 188.166.101.148 to identify infected machines requiring cleanup. The number of machines that remain compromised but un-remediated as of the publication date is not publicly reported. Users on infected machines remain at risk of having cryptocurrency wallet addresses silently substituted in their clipboard until the malware is removed.","heading":"Residual Risk: Malware Persists on Infected Machines","sources":[{"url":"https://cryptoslate.com/copy-and-paste-crypto-address-attack-remains-active-after-major-malware-cleanup-cut-off-hacker-controls/","name":"Copy and paste crypto address attack remains active after major malware cleanup — CryptoSlate","type":"news_article","credibility":2},{"url":"https://bitcoinethereumnews.com/crypto/sality-botnet-disrupted-but-crypto-stealing-malware-remains/","name":"Sality botnet disrupted, but crypto-stealing malware remains — Bitcoin Ethereum News","type":"news_article","credibility":3}],"severity":"high"},{"content":"Over its 23-year operational lifespan, the Sality botnet is linked to more than 11 million unique IP addresses. At peak activity it infected an estimated one million devices simultaneously; at the time of the 2026 disruption approximately 33,000 machines were assessed to be active nodes across two concurrent P2P protocol versions. CrowdStrike's financial analysis of the EggJagger phase (approximately 2018 to 2026) estimated confirmed minimum theft at roughly $150,000 USD (12.1 million rubles). The operator accumulated a portfolio of stolen cryptocurrency that was largely not liquidated; CrowdStrike estimated this unspent portfolio's peak nominal value at approximately $1.35 million USD (147 million rubles) in January 2025. These figures represent lower-bound estimates based on observable on-chain activity and may not capture all theft activity.","heading":"Scale and Financial Impact","sources":[{"url":"https://en.coin-turk.com/justice-department-and-crowdstrike-dismantle-sality-botnet-after-1-35-million-crypto-theft/","name":"Justice Department and CrowdStrike dismantle Sality botnet after $1.35 million crypto theft — Coin Turk","type":"news_article","credibility":3},{"url":"https://decrypt.co/377156/sality-botnet-dismantled-after-eight-years-of-stealing-bitcoin-and-ethereum","name":"Sality Botnet Dismantled After Eight Years of Stealing Bitcoin and Ethereum — Decrypt","type":"news_article","credibility":2},{"url":"https://www.europol.europa.eu/media-press/newsroom/news/global-public-private-operation-disrupts-sality-botnet-active-for-two-decades","name":"Global public-private operation disrupts Sality botnet active for two decades — Europol","type":"regulatory","credibility":1}],"severity":"critical"}],"timeline":[{"date":"2003-01-01","event":"Sality malware first identified as a polymorphic Windows executable file infector with centralized command-and-control, keylogging, and backdoor capabilities. Attributed to a Russia-based actor.","source":"CrowdStrike / Wikipedia","source_url":"https://www.crowdstrike.com/en-us/blog/who-is-salty-spider/"},{"date":"2010-01-01","event":"Sality migrates to a peer-to-peer architecture, eliminating its central C2 server. Rootkit functions added around this period.","source":"Salty Spider Threat Actor Profile — Huntress","source_url":"https://www.huntress.com/threat-library/threat-actors/salty-spider"},{"date":"2016-04-01","event":"Botnet tasked with a DDoS attack against forex2030.com.","source":"CrowdStrike — Inside the Sality Botnet Disruption Operation","source_url":"https://www.crowdstrike.com/en-us/blog/inside-sality-botnet-disruption-operation/"},{"date":"2017-01-01","event":"SALTY SPIDER reportedly ceases distribution of proxy and spambot payloads and pivots to cryptocurrency theft as primary monetization strategy.","source":"Salty Spider Threat Actor Profile — Huntress","source_url":"https://www.huntress.com/threat-library/threat-actors/salty-spider"},{"date":"2018-01-01","event":"EggJagger clipboard-hijacking payload begins deployment across the Sality botnet, targeting Bitcoin and Ethereum wallet addresses copied to victims' clipboards.","source":"CrowdStrike — Inside the Sality Botnet Disruption Operation","source_url":"https://www.crowdstrike.com/en-us/blog/inside-sality-botnet-disruption-operation/"},{"date":"2022-02-25","event":"Botnet tasked with an HTTP flood DDoS attack against kharkovforum.com, a Ukrainian web forum hosting discussion of Russia's offensive on Kharkiv, one day after Russia's full-scale invasion of Ukraine began.","source":"The Hacker News — Authorities Turn Sality's P2P Network Against Itself","source_url":"https://thehackernews.com/2026/09/authorities-turn-salitys-p2p-network.html"},{"date":"2023-09-01","event":"Botnet operator tasks a DDoS payload against AvanChange, a Russian cryptocurrency exchange. CrowdStrike noted the payload was compiled seconds before upload, suggesting a personal grievance rather than strategic planning.","source":"CrowdStrike — Inside the Sality Botnet Disruption Operation","source_url":"https://www.crowdstrike.com/en-us/blog/inside-sality-botnet-disruption-operation/"},{"date":"2025-01-01","event":"CrowdStrike estimates the operator's unspent stolen cryptocurrency portfolio peaks at approximately 147 million rubles ($1.35 million USD nominal value).","source":"Decrypt — Sality Botnet Dismantled After Eight Years of Stealing Bitcoin and Ethereum","source_url":"https://decrypt.co/377156/sality-botnet-dismantled-after-eight-years-of-stealing-bitcoin-and-ethereum"},{"date":"2026-08-31","event":"CrowdStrike's Counter Adversary Operations team, with the DOJ, FBI, Defense Criminal Investigative Service, and law enforcement from Bulgaria, Hungary, and Romania, executes a peer-to-peer sinkholing operation. More than 15,000 infected machines severed from the botnet. Sality-linked domains seized in the U.S. and Europe. No arrests announced.","source":"U.S. Department of Justice — Sality Malware Disrupted in International Cyber Takedown","source_url":"https://www.justice.gov/usao-cdca/pr/sality-malware-disrupted-international-cyber-takedown"},{"date":"2026-09-02","event":"DOJ, Europol, and CrowdStrike publicly announce the Sality botnet disruption. CrowdStrike researcher Tillmann Werner describes the operation as the most complex botnet takedown the company had ever conducted.","source":"Europol — Global public-private operation disrupts Sality botnet active for two decades","source_url":"https://www.europol.europa.eu/media-press/newsroom/news/global-public-private-operation-disrupts-sality-botnet-active-for-two-decades"},{"date":"2026-09-02","event":"Security researchers note that EggJagger and other Sality components remain active on previously infected machines pending manual remediation. CrowdStrike publishes the sinkhole IP address (188.166.101.148) to assist with detection.","source":"CryptoSlate — Copy and paste crypto address attack remains active after major malware cleanup","source_url":"https://cryptoslate.com/copy-and-paste-crypto-address-attack-remains-active-after-major-malware-cleanup-cut-off-hacker-controls/"}],"sources_used":[{"url":"https://www.justice.gov/usao-cdca/pr/sality-malware-disrupted-international-cyber-takedown","name":"Sality Malware Disrupted in International Cyber Takedown — U.S. Department of Justice","type":"regulatory","archive_url":"http://web.archive.org/web/20260905025341/https://www.justice.gov/usao-cdca/pr/sality-malware-disrupted-international-cyber-takedown","credibility":1,"archive_timestamp":"2026-09-05T02:53:41+00:00"},{"url":"https://www.europol.europa.eu/media-press/newsroom/news/global-public-private-operation-disrupts-sality-botnet-active-for-two-decades","name":"Global public-private operation disrupts Sality botnet active for two decades — Europol","type":"regulatory","archive_url":"http://web.archive.org/web/20260905015638/https://www.europol.europa.eu/media-press/newsroom/news/global-public-private-operation-disrupts-sality-botnet-active-for-two-decades","credibility":1,"archive_timestamp":"2026-09-05T01:56:38+00:00"},{"url":"https://www.crowdstrike.com/en-us/blog/inside-sality-botnet-disruption-operation/","name":"Peer Pressure: Inside the Sality Botnet Disruption Operation — CrowdStrike","type":"research","archive_url":"http://web.archive.org/web/20260905015422/https://www.crowdstrike.com/en-us/blog/inside-sality-botnet-disruption-operation/","credibility":2,"archive_timestamp":"2026-09-05T01:54:22+00:00"},{"url":"https://www.crowdstrike.com/en-us/blog/who-is-salty-spider/","name":"Who is SALTY SPIDER? — CrowdStrike","type":"research","archive_url":"http://web.archive.org/web/20260905020129/https://www.crowdstrike.com/en-us/blog/who-is-salty-spider/","credibility":2,"archive_timestamp":"2026-09-05T02:01:29+00:00"},{"url":"https://www.crowdstrike.com/en-us/adversaries/salty-spider/","name":"Salty Spider Adversary Profile — CrowdStrike","type":"research","archive_url":"https://web.archive.org/web/20260916000931/https://www.crowdstrike.com/en-us/adversaries/salty-spider/","credibility":2,"archive_timestamp":"2026-09-16T00:09:31+00:00"},{"url":"https://therecord.media/sality-botnet-cyber-doj","name":"Sality, one of the longest-running botnets, finally gets disrupted — The Record (Recorded Future)","type":"news_article","archive_url":"http://web.archive.org/web/20260902134555/https://therecord.media/sality-botnet-cyber-doj","credibility":1,"archive_timestamp":"2026-09-02T13:45:55+00:00"},{"url":"https://www.bleepingcomputer.com/news/security/sality-botnet-infrastructure-dismantled-in-joint-global-takedown/","name":"Sality botnet infrastructure dismantled in joint global takedown — BleepingComputer","type":"news_article","archive_url":"http://web.archive.org/web/20260914115220/https://www.bleepingcomputer.com/news/security/sality-botnet-infrastructure-dismantled-in-joint-global-takedown/","credibility":2,"archive_timestamp":"2026-09-14T11:52:20+00:00"},{"url":"https://decrypt.co/377156/sality-botnet-dismantled-after-eight-years-of-stealing-bitcoin-and-ethereum","name":"Sality Botnet Dismantled After Eight Years of Stealing Bitcoin and Ethereum — Decrypt","type":"news_article","archive_url":"http://web.archive.org/web/20260905022837/https://decrypt.co/377156/sality-botnet-dismantled-after-eight-years-of-stealing-bitcoin-and-ethereum","credibility":2,"archive_timestamp":"2026-09-05T02:28:37+00:00"},{"url":"https://www.coindesk.com/tech/2026/09/02/crowdstrike-and-federal-authorities-dismantle-russian-malware-that-secretly-stole-crypto-for-8-years","name":"CrowdStrike and federal authorities dismantle Russian malware that secretly stole crypto for 8 years — CoinDesk","type":"news_article","archive_url":"https://web.archive.org/web/20260916000909/https://www.coindesk.com/tech/2026/09/02/crowdstrike-and-federal-authorities-dismantle-russian-malware-that-secretly-stole-crypto-for-8-years","credibility":2,"archive_timestamp":"2026-09-16T00:09:09+00:00"},{"url":"https://www.helpnetsecurity.com/2026/09/02/sality-botnet-disruption-crowdstrike-law-enforcement/","name":"Global sinkhole operation ends Sality botnet's 23-year run — Help Net Security","type":"news_article","archive_url":"http://web.archive.org/web/20260905120634/https://www.helpnetsecurity.com/2026/09/02/sality-botnet-disruption-crowdstrike-law-enforcement/","credibility":2,"archive_timestamp":"2026-09-05T12:06:34+00:00"},{"url":"https://thehackernews.com/2026/09/authorities-turn-salitys-p2p-network.html","name":"Authorities Turn Sality's P2P Network Against Itself — The Hacker News","type":"news_article","archive_url":"http://web.archive.org/web/20260911192958/https://thehackernews.com/2026/09/authorities-turn-salitys-p2p-network.html","credibility":2,"archive_timestamp":"2026-09-11T19:29:58+00:00"},{"url":"https://www.cybersecuritydive.com/news/doj-crowdstrike-botnet-sality-takedown/829512/","name":"Government, industry partner to shut down long-running Sality botnet — Cybersecurity Dive","type":"news_article","archive_url":"http://web.archive.org/web/20260914115114/https://www.cybersecuritydive.com/news/doj-crowdstrike-botnet-sality-takedown/829512/","credibility":2,"archive_timestamp":"2026-09-14T11:51:14+00:00"},{"url":"https://www.huntress.com/threat-library/threat-actors/salty-spider","name":"Salty Spider Threat Actor Profile — Huntress","type":"research","archive_url":"http://web.archive.org/web/20260515172250/https://www.huntress.com/threat-library/threat-actors/salty-spider","credibility":2,"archive_timestamp":"2026-05-15T17:22:50+00:00"},{"url":"https://malpedia.caad.fkie.fraunhofer.de/actor/salty_spider","name":"SALTY SPIDER — Malpedia","type":"research","archive_url":"http://web.archive.org/web/20260609113915/https://malpedia.caad.fkie.fraunhofer.de/actor/salty_spider","credibility":2,"archive_timestamp":"2026-06-09T11:39:15+00:00"},{"url":"https://cryptoslate.com/copy-and-paste-crypto-address-attack-remains-active-after-major-malware-cleanup-cut-off-hacker-controls/","name":"Copy and paste crypto address attack remains active after major malware cleanup — CryptoSlate","type":"news_article","archive_url":"http://web.archive.org/web/20260909174314/https://cryptoslate.com/copy-and-paste-crypto-address-attack-remains-active-after-major-malware-cleanup-cut-off-hacker-controls/","credibility":2,"archive_timestamp":"2026-09-09T17:43:14+00:00"},{"url":"https://cointelegraph.com/news/us-officials-crowdstrike-malware-stealing-crypto","name":"US Officials Work with CrowdStrike to Fight Malware behind Crypto Theft — CoinTelegraph","type":"news_article","archive_url":"http://web.archive.org/web/20260905091344/https://cointelegraph.com/news/us-officials-crowdstrike-malware-stealing-crypto","credibility":2,"archive_timestamp":"2026-09-05T09:13:44+00:00"},{"url":"https://99bitcoins.com/news/scams-theft/sality-botnet-takedown-crypto/","name":"Sality Botnet Takedown and EggJagger Crypto Theft — 99Bitcoins","type":"news_article","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-09-15T17:08:08.43781+00:00","updated_at":"2026-09-16T00:12:21.501842+00:00"}}