2026-09-02 CoinTelegraph

US and CrowdStrike Disrupt Sality Botnet Behind $150K Crypto Theft

Federal law enforcement officials, working alongside cybersecurity firm CrowdStrike and the Shadowserver Foundation, announced the disruption of the Sality botnet, a malware network responsible for stealing approximately $150,000 in cryptocurrency over the past eight years. In a Tuesday notice, the US Justice Department confirmed the operation was carried out in coordination with Bulgarian, Hungarian, and Romanian authorities, targeting infrastructure that had been active since 2003.

According to CrowdStrike, the operators behind Sality deployed EggJagger, a clipjacking tool that silently swaps cryptocurrency wallet addresses on victims' clipboards with addresses controlled by the attackers. When users copied a Bitcoin or Ethereum address to complete a transaction, the funds were redirected without their knowledge. The stolen assets, totaling at least 12.1 million rubles, peaked in value at approximately $1.5 million in January 2025 before being moved or laundered. The malware infected roughly 15,000 computers, forming a peer-to-peer botnet that checked the status of its systems every 40 minutes.

Following the coordinated takedown, CrowdStrike reported that the criminals behind Sality lost the ability to communicate with infected machines, effectively neutralizing the network's command-and-control infrastructure. US officials confirmed the malware had been used for both crypto theft and broader cyberattacks on compromised devices. The operation marks one of the latest cross-border efforts by international agencies and private-sector partners to dismantle long-running botnets targeting digital asset holders.

Read Full Article at CoinTelegraph →

Related Tool

Find Your ID

Try Now →
Check My ID