Federal law enforcement officials, working with cybersecurity technology company CrowdStrike, have announced action against the entity behind the malware that enabled the theft of $150,000 in cryptocurrency.
The US Department of Justice announced this information in a notification on Tuesday said It disrupted the Sality botnet and malware in an international effort with Bulgarian, Hungarian and Romanian officials as well as private sector partners CrowdStrike and the ShadowServer Foundation. US officials said Sality was responsible for installing malware on compromised devices since 2003, leading to crypto theft and cyber attacks.
Crowdstrike Report Over the previous eight years, the companies behind Sally used EggJagger, a “clipjacking tool that monitors clipboards for cryptocurrency wallet addresses and silently replaces them with addresses controlled by the operator,” to steal at least 12.1 million rubles, or about $150,000, in cryptocurrency. According to the company, the value of “never spent” digital assets reached about $1.5 million in January 2025.
“When a victim copies a Bitcoin or Ethereum address to make a payment, the funds are redirected,” CrowdStrike said, explaining the strategy behind the theft.
According to CrowdStrike, the authorities’ efforts to disrupt the network resulted in the criminals behind Sally “losing the ability to communicate with infected machines”. US officials and the company said Sality was used to steal crypto, while about 15,000 infected computers formed part of a peer-to-peer botnet that checked its systems every 40 minutes to see if they were online.
Related: A fake crypto job interview Malware has almost been installed on my computer
