US Officials Disrupt Sality Botnet with CrowdStrike to Counter Crypto Theft

iconCryptoBreaking
Share
AI summary iconSummary
US officials, working with CrowdStrike and CFT-focused international partners, disrupted the Sality botnet to protect liquidity and crypto markets. The malware, active for over 20 years, used clipjacking to steal crypto from infected systems. The botnet, spread across Bulgaria, Hungary, and Romania, controlled about 15,000 machines and siphoned 12.1 million rubles ($150,000) over eight years. The operation highlights global efforts to secure digital assets against cyber threats.
Us Officials Coordinate With Crowdstrike To Counter Crypto Theft Malware

US federal law enforcement, in cooperation with cybersecurity company CrowdStrike and international partners, announced an operation targeting the Sality malware ecosystem—an infection chain authorities say has been used for more than two decades to steal cryptocurrency and carry out cyberattacks.

In a Tuesday announcement, the US Department of Justice (DOJ) said it disrupted the Sality botnet and related malware in an international effort involving Bulgarian, Hungarian, and Romanian officials, as well as private-sector partners CrowdStrike and the Shadowserver Foundation. The DOJ linked Sality to long-running compromise activity dating back to 2003, including the installation of malware on affected devices.

Key takeaways

  • The DOJ says the Sality botnet and malware infrastructure were disrupted through a coordinated international takedown.
  • CrowdStrike reports that clipboard-based “clipjacking” was used to replace cryptocurrency addresses with attacker-controlled ones.
  • According to CrowdStrike, entities behind Sality stole at least 12.1 million rubles (about $150,000) over the prior eight years.
  • Authorities described a peer-to-peer botnet of roughly 15,000 infected computers that periodically checked whether targets were online.
  • During the operation, Sality operators reportedly lost the ability to communicate with infected machines.

Why clipboard hijacking matters for crypto security

The most consequential detail in the reporting is how the theft worked. CrowdStrike said that in the previous eight years, the operators used EggJagger, a clipjacking tool that monitors a victim’s clipboard for cryptocurrency wallet addresses and then silently swaps them for addresses controlled by the attacker.

In practical terms, the mechanism targets a common user behavior: copying and pasting wallet addresses when sending funds. According to CrowdStrike, when a victim copies a Bitcoin or Ethereum address to complete a payment, the funds are redirected to the substituted address.

This type of attack is particularly damaging because it doesn’t require the victim to sign malicious transactions or interact with a fake website in the moment. Instead, it compromises the transaction flow at the point of address entry—meaning users who rely on clipboard copy/paste can be tricked even if they never knowingly interact with malware prompts or phishing pages.

Scope and reported impact of the Sality operation

In its write-up on the takedown, CrowdStrike said that the clipjacking approach enabled theft of at least 12.1 million rubles, or roughly $150,000 in cryptocurrency, during the period it described. The company also emphasized that stolen assets remained “never-spent,” meaning the seized digital funds were not later spent or otherwise moved from the attacker-linked destinations in the observed timeframe.

It further stated that the value of these “never-spent” assets peaked at about $1.5 million in January 2025, giving a sense of how significant the stored proceeds could become once operational theft processes are running.

While the reported theft amount and peak valuation describe only what CrowdStrike observed in its analysis, they help clarify why disrupting the botnet’s communication channels is so important: if operators can’t reliably control or maintain infections, their ability to trigger address substitutions and collect funds diminishes.

How the botnet functioned—and what the disruption changed

US officials and CrowdStrike both described Sality as a peer-to-peer botnet. According to the company, about 15,000 infected computers were part of this network, which checked whether systems were online every 40 minutes. That periodic connectivity helped ensure the malware operators could maintain visibility into infection status and, when possible, continue malicious operations.

After the authorities’ efforts, CrowdStrike said the criminals “lost the ability to communicate with infected machines.” In botnet operations, that loss is often decisive: even if infected devices remain in place temporarily, removing command-and-control communications reduces the malware’s ability to coordinate, update, and execute its most profitable functions.

The DOJ’s announcement framed the disruption as part of a broader disruption of Sality malware and the botnet infrastructure tied to it, not just a removal of individual infections. For crypto users, the key takeaway is that these campaigns can persist for long periods—DOJ said Sality was responsible for installing malware on compromised devices since 2003—so enforcement actions and technical disruptions are critical for shrinking the attacker’s operational surface.

What investors and users should watch next

This takedown highlights how cryptocurrency theft campaigns increasingly blend malware distribution with human workflow attacks like clipboard hijacking. Users should treat clipboard-based address substitution as a real threat—especially when sending Bitcoin or Ethereum funds—and consider validating recipient addresses through out-of-band methods (for example, checking a pasted address against a trusted source or using verification steps in wallet software).

Looking ahead, the open question is how attackers adapt if their ability to communicate with infected machines is curtailed. Readers should watch for follow-on malware variants, new clipboard hijacking tools, or broader changes in how criminals maintain access to victim devices as the Sality infrastructure disruption ripples through criminal operations.

This article was originally published as US Officials Coordinate With CrowdStrike to Counter Crypto Theft Malware on Crypto Breaking News – your trusted source for crypto news, Bitcoin news, and blockchain updates.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.