US Officials Collaborate with CrowdStrike to Combat Malware Responsible for Crypto Theft

US federal law enforcement officials, working together with cybersecurity firm CrowdStrike, have announced the disruption of the Sality malware responsible for infecting machines since 2003 and facilitating cryptocurrency theft exceeding $150,000. This international operation involved cooperation with authorities from Bulgaria, Hungary, Romania, and private sector partners CrowdStrike and the Shadowserver Foundation.
International Operation to Dismantle Sality
On Tuesday, the US Department of Justice announced a multinational operation targeting the disruption of the Sality botnet. The effort included law enforcement from Bulgaria, Hungary, Romania, alongside technology firms CrowdStrike and the Shadowserver Foundation.
The operation aimed to destabilize Sality, malware active since 2003 that infected users' devices, facilitating cryptocurrency theft and enabling cyberattacks.
The EggJagger Clipboard Hijacking Technique
CrowdStrike’s analysis revealed that over the past eight years, the criminals behind Sality used a tool named EggJagger, a clipboard hijacking method that monitors clipboard content for cryptocurrency wallet addresses and quietly replaces them with addresses controlled by the operators.
This method redirected payments when victims copied Bitcoin or Ethereum addresses for transactions, resulting in at least 12.1 million rubles (approximately $150,000) stolen in cryptocurrency.
Damage and Technical Details of the Malware
According to CrowdStrike, the total value of stolen but never-spent digital assets peaked around $1.5 million in January 2025.
About 15,000 infected computers formed a peer-to-peer botnet, which checked connectivity every 40 minutes to maintain communication between the malware and its operators.
Due to the coordinated action of law enforcement and CrowdStrike, the criminals lost their ability to communicate with infected machines.
Why it matters
This news highlights the effectiveness of international cooperation between law enforcement agencies and cybersecurity firms in combating cybercrime and protecting cryptocurrency assets. The detection and disruption of malware such as Sality and its associated tool EggJagger are crucial for preventing large-scale digital asset theft. The situation underscores the threats posed by malware capable of automatically intercepting crypto wallet addresses, emphasizing the need for continuous monitoring and response mechanisms to enhance cryptocurrency user security.
Prepared from the source material with AI-assisted editing and checked against the supplied facts.
Open original source ↗