EggJagger is a cryptocurrency clipboard hijacker, or clipper, primarily distributed by the Sality peer-to-peer botnet for approximately eight years. It monitors an infected system’s clipboard for copied cryptocurrency wallet addresses, including Bitcoin and Ethereum addresses, and silently replaces them with wallet addresses controlled by the operator. This substitution can redirect a victim’s intended cryptocurrency payment to the attacker when the altered address is not identified before a transaction is confirmed. CrowdStrike associates Sality activity with the financially motivated criminal group SALTY SPIDER and estimates that EggJagger generated at least $150,000 in stolen cryptocurrency. EggJagger has been delivered to systems compromised by Sality, a long-running Windows file-infecting malware family and botnet.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
For approximately the past eight years, CrowdStrike said its primary payload was EggJagger, a clipboard-hijacking tool that monitored devices for copied cryptocurrency wallet addresses.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cryptocurrency theft payload delivered primarily through Sality. It monitors clipboard contents for cryptocurrency wallet addresses and substitutes attacker-controlled addresses, redirecting cryptocurrency transfers.
A clipboard-hijacking payload distributed by Sality that detects copied Bitcoin and Ethereum wallet addresses and substitutes attacker-controlled addresses, diverting cryptocurrency transfers.
Cryptocurrency clipboard-hijacking malware delivered as Sality's primary payload. It replaces copied Bitcoin or Ethereum wallet addresses with attacker-controlled addresses to divert payments.
A cryptocurrency clipboard hijacker distributed by Sality that replaces copied wallet addresses with attacker-controlled addresses to divert cryptocurrency payments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.