US, CrowdStrike Disrupt Sality Botnet Behind $150K Crypto Theft
Federal law enforcement officials, working alongside cybersecurity firm CrowdStrike and the Shadowserver Foundation, announced on Tuesday that they had disrupted the Sality botnet, a malware network active since 2003 that facilitated cryptocurrency theft and a wide range of cyberattacks. The US Justice Department coordinated the operation with law enforcement counterparts in Bulgaria, Hungary, and Romania to dismantle the infrastructure behind one of the longest-running peer-to-peer botnets in existence.
According to CrowdStrike's analysis, operators of the Sality botnet deployed a clipjacking tool known as EggJagger, which monitors victims' clipboards for cryptocurrency wallet addresses and silently swaps them with attacker-controlled addresses. Over the past eight years, this technique enabled the theft of approximately 12.1 million rubles, or roughly $150,000, in digital assets. CrowdStrike noted that the combined value of unredeemed stolen funds peaked at around $1.5 million in January 2025.
The operation also severed command-and-control communications for roughly 15,000 infected machines that had formed part of the Sality peer-to-peer botnet, which routinely checked in with peers every 40 minutes to verify connectivity. CrowdStrike confirmed that operators behind the malware "lost the ability to communicate with infected machines" as a direct result of the coordinated takedown. The case underscores the persistent threat posed by clipboard-hijacking malware targeting Bitcoin and Ethereum users, a tactic that remains effective even as cybersecurity defenses evolve.
Read Full Article at CoinTelegraph →