US officials work with CrowdStrike to fight crypto theft malware
Direct answer: U.S. federal law enforcement officials work with CrowdStrike and other private-sector partners to disrupt the Sality botnet, long-running malware that redirected roughly $150,000 in cryptocurrency over the past eight years by swapping copied Bitcoin and Ethereum wallet addresses on infected devices before payments could be sent.
Key Takeaways
- The U.S. Justice Department disrupted the Sality botnet in a multinational operation with Bulgaria, Hungary, Romania, CrowdStrike, and the Shadowserver Foundation.
- EggJagger, a clipboard-hijacking tool, silently replaced wallet addresses and stole at least $150,000 in crypto over eight years.
- About 15,000 infected computers formed a peer-to-peer botnet that checked connectivity every 40 minutes.
- Operators behind Sality lost the ability to communicate with compromised machines after the disruption.
- Unspent stolen crypto holdings linked to the campaign peaked at about $1.5 million in January 2025.
What Did U.S. Officials and CrowdStrike Announce?
Federal law enforcement officials, working with cybersecurity firm CrowdStrike, announced action against entities behind malware that enabled the theft of $150,000 in cryptocurrency. In a Tuesday notice, the U.S. Justice Department said it had disrupted the Sality botnet and malware in an international effort with Bulgarian, Hungarian, and Romanian officials.
Private-sector partners CrowdStrike and the Shadowserver Foundation also took part. U.S. officials said Sality had installed malware on compromised devices since 2003, fueling crypto theft and broader cyberattacks. For more on threats targeting digital assets, see our Fintech & Crypto Alerts coverage.
How Did the Sality Malware Steal Cryptocurrency?
CrowdStrike reported that over the previous eight years, the entities behind Sality used EggJagger, described as a clipjacking tool that monitors the clipboard for cryptocurrency wallet addresses and silently replaces them with addresses controlled by the operator. The firm estimates at least 12.1 million rubles, or about $150,000, was stolen through this method.
When a victim copies a Bitcoin or Ethereum address to make a payment, the funds are redirected to the criminal operator instead of the intended recipient. According to CrowdStrike, the value of never-spent digital assets linked to the campaign peaked at about $1.5 million in January 2025.
How Was the Botnet Disrupted?
According to CrowdStrike, the criminals behind Sality lost the ability to communicate with infected machines as authorities worked to disrupt the network. U.S. officials and the company said roughly 15,000 infected computers formed part of a peer-to-peer botnet that checked whether its systems were online every 40 minutes.
The coordinated takedown highlights how public-private partnerships can target long-running criminal infrastructure. Full details are available in the original Cointelegraph report and from federal authorities.
Why Does This Operation Matter for Crypto Users?
The disruption targets a botnet that has operated since 2003, with crypto-focused theft running through EggJagger for the past eight years. Confirmed losses tied to the clipjacking payload reached about $150,000, while associated unspent holdings climbed far higher before the takedown.
Federal authorities and private-sector partners were part of an operation to disrupt malware that redirected funds by replacing wallet addresses at the moment users copied them for Bitcoin or Ethereum payments. The case underscores ongoing risks from malware on everyday devices used to move digital assets.