{
  "story_id": "6374f312a594b1403ccd89251cbcb85d",
  "desk": "drm3",
  "revision": 1,
  "published_at": "2026-09-02T13:50:55.000Z",
  "content_hash": "d1b48745f477f1757141b0ac825d00e7fcffe8b5ab95bf1338a7d28f6b2d46b6",
  "hash_basis": "sha256 over `headline\\ndek\\nprose`, plus `\\n` + the canonical citations JSON when any source is placed, plus `\\n#blog` for blogs",
  "basis": {
    "headline": "US and European Authorities Dismantle Sality Bitcoin Botnet",
    "dek": "Justice Department and CrowdStrike disrupted Sality botnet after eight years of stealing cryptocurrency.",
    "prose": "The Justice Department and CrowdStrike announced on Tuesday that they had disrupted Sality, a peer-to-peer botnet that has been running since 2003. [^1]\n\nCrowdStrike estimates that the Sality operator stole at least $150,000 through its primary payload, EggJagger, over the past eight years. [^2]\n\nCrowdStrike values the unspent stolen cryptocurrency portfolio at a peak of about 147 million rubles in January 2025, which is roughly the purchasing power of $4 million in a Western capital. [^3]\n\nThe EggJagger payload monitors the clipboard for cryptocurrency wallet addresses and swaps them for the operator's own addresses, causing victims to send funds to strangers. [^4]\n\nThe EggJagger tool monitored a victim's clipboard for cryptocurrency wallet addresses and silently replaced them with addresses controlled by the operator, allowing funds to be redirected before a payment was completed. [^5]\n\nThe Sality botnet has been active since 2003 and evolved into a peer-to-peer network where infected machines communicate directly with one another rather than relying on a central command-and-control server. [^6]",
    "cited": "[{\"statement\":\"The Justice Department and CrowdStrike announced on Tuesday that they had disrupted Sality, a peer-to-peer botnet that has been running since 2003.\",\"source\":\"Decrypt\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-02T11:30:45.000Z\",\"publisher_count\":1,\"sources\":[\"Decrypt\"]},{\"statement\":\"CrowdStrike estimates that the Sality operator stole at least $150,000 through its primary payload, EggJagger, over the past eight years.\",\"source\":\"Decrypt\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-02T11:30:45.000Z\",\"publisher_count\":1,\"sources\":[\"Decrypt\"]},{\"statement\":\"CrowdStrike values the unspent stolen cryptocurrency portfolio at a peak of about 147 million rubles in January 2025, which is roughly the purchasing power of $4 million in a Western capital.\",\"source\":\"Decrypt\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-02T11:30:45.000Z\",\"publisher_count\":1,\"sources\":[\"Decrypt\"]},{\"statement\":\"The EggJagger payload monitors the clipboard for cryptocurrency wallet addresses and swaps them for the operator's own addresses, causing victims to send funds to strangers.\",\"source\":\"Decrypt\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-02T11:30:45.000Z\",\"publisher_count\":1,\"sources\":[\"Decrypt\"]},{\"statement\":\"The EggJagger tool monitored a victim's clipboard for cryptocurrency wallet addresses and silently replaced them with addresses controlled by the operator, allowing funds to be redirected before a payment was completed.\",\"source\":\"99Bitcoins\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-02T13:50:55.000Z\",\"publisher_count\":1,\"sources\":[\"99Bitcoins\"]},{\"statement\":\"The Sality botnet has been active since 2003 and evolved into a peer-to-peer network where infected machines communicate directly with one another rather than relying on a central command-and-control server.\",\"source\":\"99Bitcoins\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-02T13:50:55.000Z\",\"publisher_count\":1,\"sources\":[\"99Bitcoins\"]}]",
    "kind": "news"
  },
  "receipt_verify": "Ed25519 over the dot-joined string `slice_hash.cursor_from.cursor_to.view.view_version.row_count`; public_key and sig are base64url of the raw 32-byte key / 64-byte signature",
  "receipt": null,
  "receipt_note": "this revision predates receipt-keeping (before v0.37.0); the filed row lives in the record",
  "generation_chain": {
    "wire": {
      "stream": "fountain_news",
      "story_id": "b53ed1fd94ad7388412df3553056e20b",
      "thread_id": "bc05ca923e18eeb9a587ad51615ec26c",
      "thread_label": "SALTY SPIDER",
      "novelty": "UPDATE",
      "content_hash": "0914fb56d45367f939d30357f9f3a7d4c60c9b545f1de7df693518881232941f",
      "last_published_at": "2026-09-02T13:50:55.000Z",
      "read_receipt": {
        "slice_hash": "48b2e0c3af4a8626da2fc811245788ff6e4271281efe8c00f25b0b05bb9edcc0",
        "cursor_from": "eyJ0cyI6IjIwMjYtMDktMDJUMTM6MjE6NDUuMDAwMDAwWiIsImlkIjoiY2FjYjg1OTkyMDViN2I3MWM0YzhmYmUyYWMyZDA1OWYiLCJ2IjoiMSJ9",
        "cursor_to": "eyJ0cyI6IjIwMjYtMDktMDJUMTM6NTU6MDUuMDAwMDAwWiIsImlkIjoiYWNhYmYyOWI5NzVlYzQwOTE2ZmQ0ODdhYWJiMGRmZGIiLCJ2IjoiMSJ9",
        "view": "v_fountain_news",
        "view_version": "1",
        "row_count": 100,
        "window_days": 3,
        "bytes_scanned": 10113494,
        "credits": 8,
        "price_per_100_rows": 8,
        "sig": "1xwVD3uooFyxoSm6LPZf4A-bZFY74_s3o2sTcCuvLGZGzHvwRVCTx4NMLW2iH70kOvIw6hJoMKWNufYnsOQvDw",
        "public_key": "bMUigy8O0jOnBxQ4Sc-5lwhIZ8LQVAhxMbR7qESVuUE",
        "signer_path": "lakehouse/data-extract/v1",
        "alg": "Ed25519",
        "signed": true
      }
    },
    "written_at": "2026-09-03T00:31:40.953Z"
  },
  "cited_facts": [
    {
      "statement": "The Justice Department and CrowdStrike announced on Tuesday that they had disrupted Sality, a peer-to-peer botnet that has been running since 2003.",
      "source": "Decrypt",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-02T11:30:45.000Z",
      "publisher_count": 1,
      "sources": [
        "Decrypt"
      ]
    },
    {
      "statement": "CrowdStrike estimates that the Sality operator stole at least $150,000 through its primary payload, EggJagger, over the past eight years.",
      "source": "Decrypt",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-02T11:30:45.000Z",
      "publisher_count": 1,
      "sources": [
        "Decrypt"
      ]
    },
    {
      "statement": "CrowdStrike values the unspent stolen cryptocurrency portfolio at a peak of about 147 million rubles in January 2025, which is roughly the purchasing power of $4 million in a Western capital.",
      "source": "Decrypt",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-02T11:30:45.000Z",
      "publisher_count": 1,
      "sources": [
        "Decrypt"
      ]
    },
    {
      "statement": "The EggJagger payload monitors the clipboard for cryptocurrency wallet addresses and swaps them for the operator's own addresses, causing victims to send funds to strangers.",
      "source": "Decrypt",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-02T11:30:45.000Z",
      "publisher_count": 1,
      "sources": [
        "Decrypt"
      ]
    },
    {
      "statement": "The EggJagger tool monitored a victim's clipboard for cryptocurrency wallet addresses and silently replaced them with addresses controlled by the operator, allowing funds to be redirected before a payment was completed.",
      "source": "99Bitcoins",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-02T13:50:55.000Z",
      "publisher_count": 1,
      "sources": [
        "99Bitcoins"
      ]
    },
    {
      "statement": "The Sality botnet has been active since 2003 and evolved into a peer-to-peer network where infected machines communicate directly with one another rather than relying on a central command-and-control server.",
      "source": "99Bitcoins",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-02T13:50:55.000Z",
      "publisher_count": 1,
      "sources": [
        "99Bitcoins"
      ]
    }
  ],
  "note": "A signature proves who filed this and that it has not changed since. It never makes a claim true."
}