US federal law enforcement officials, working with cybersecurity company CrowdStrike, announced action against entities behind malware that enabled cryptocurrency theft.
In a Tuesday notice, the US Department of Justice said it disrupted the Sality botnet and related malware in an international operation involving officials from Bulgaria, Hungary and Romania, as well as private-sector partners CrowdStrike and the Shadowserver Foundation.
US officials said Sality had been installing malware on compromised devices since 2003, leading to crypto theft and cyberattacks.
EggJagger was used to replace copied wallet addresses
CrowdStrike said the entities behind Sality used EggJagger during the past eight years. The company described it as a clipjacking tool that watches the clipboard for cryptocurrency wallet addresses and silently swaps them for addresses controlled by the operator.
According to CrowdStrike, the tool stole at least 12.1 million rubles, or about $150,000, in cryptocurrency. The company also said the value of those never-spent digital assets peaked at about $1.5 million in January 2025.
「When a victim copies a Bitcoin or Ethereum address to make a payment, the funds are redirected」, CrowdStrike said, describing how the theft worked.
Authorities said the operators lost contact with infected devices
CrowdStrike said the disruption left the criminals behind Sality unable to communicate with infected machines.
US officials and the company said Sality was used to steal cryptocurrency, while about 15,000 infected computers formed part of a peer-to-peer botnet that checked whether its systems were online every 40 minutes.

