US Justice Department and CrowdStrike move against Sality malware tied to crypto theft

US Justice Department and CrowdStrike move against Sality malware tied to crypto theft

N
News Editor
2026-09-02 21:27:15
US federal authorities, working with cybersecurity firm CrowdStrike and international partners, said they disrupted the Sality botnet and related malware linked to cryptocurrency theft and other cyberattacks. The Justice Department said the effort involved officials in Bulgaria, Hungary and Romania, along with private-sector partners CrowdStrike and the Shadowserver Foundation. According to CrowdStrike, operators behind Sality used EggJagger over the past eight years, a clipjacking tool that monitored copied wallet addresses and silently replaced them with addresses under the attackers’ control. The company said the campaign stole at least 12.1 million rubles, or about $150,000, in cryptocurrency. It also said the value of the digital assets that were never spent reached about $1.5 million in January 2025. Authorities and CrowdStrike added that the disruption caused the operators to lose the ability to communicate with infected machines. Roughly 15,000 compromised computers were part of a peer-to-peer botnet that checked whether its systems were online every 40 minutes.

US federal law enforcement officials, working with cybersecurity company CrowdStrike, announced action against entities behind malware that enabled cryptocurrency theft.

In a Tuesday notice, the US Department of Justice said it disrupted the Sality botnet and related malware in an international operation involving officials from Bulgaria, Hungary and Romania, as well as private-sector partners CrowdStrike and the Shadowserver Foundation.

US officials said Sality had been installing malware on compromised devices since 2003, leading to crypto theft and cyberattacks.

EggJagger was used to replace copied wallet addresses

CrowdStrike said the entities behind Sality used EggJagger during the past eight years. The company described it as a clipjacking tool that watches the clipboard for cryptocurrency wallet addresses and silently swaps them for addresses controlled by the operator.

According to CrowdStrike, the tool stole at least 12.1 million rubles, or about $150,000, in cryptocurrency. The company also said the value of those never-spent digital assets peaked at about $1.5 million in January 2025.

「When a victim copies a Bitcoin or Ethereum address to make a payment, the funds are redirected」, CrowdStrike said, describing how the theft worked.

Authorities said the operators lost contact with infected devices

CrowdStrike said the disruption left the criminals behind Sality unable to communicate with infected machines.

US officials and the company said Sality was used to steal cryptocurrency, while about 15,000 infected computers formed part of a peer-to-peer botnet that checked whether its systems were online every 40 minutes.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
1100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.