Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

US Law Enforcement Disrupts Sality Botnet Behind $150,000 Crypto Theft

Federal authorities and CrowdStrike announced the disruption of a malware operation that stole cryptocurrency using a clipboard-hijacking tool, with stolen assets peaking at $1.5 million.
5 days ago 23 views
US Law Enforcement Disrupts Sality Botnet Behind $150,000 Crypto Theft

Federal law enforcement officials, working with cybersecurity firm CrowdStrike, announced action against entities behind a malware operation that enabled the theft of $150,000 in cryptocurrency.

The US Justice Department disrupted the Sality botnet and malware in an international effort coordinated with officials from Bulgaria, Hungary, and Romania, as well as private sector partners CrowdStrike and the Shadowserver Foundation. According to US authorities, Sality had been responsible for installing malware on compromised devices since 2003, resulting in cryptocurrency theft and cyberattacks.

Clipboard-Hijacking Technique

CrowdStrike reported that over the previous eight years, operators behind Sality used EggJagger, a tool designed to monitor clipboards for cryptocurrency wallet addresses and replace them with addresses controlled by the attackers. The technique enabled the theft of at least 12.1 million rubles, approximately $150,000 in cryptocurrency.

When a victim copies a Bitcoin or Ethereum address to make a payment, the funds are redirected to attacker-controlled wallets, CrowdStrike explained. The value of the stolen digital assets that remained unspent peaked at approximately $1.5 million in January 2025.

Network Disruption

As a result of the coordinated disruption effort, criminals behind Sality lost the ability to communicate with infected machines. Approximately 15,000 infected computers had formed part of a peer-to-peer botnet that checked whether its systems were online every 40 minutes.

Market snapshot

Top cryptocurrency prices

Explore all prices
Market prices will appear after the next scheduled refresh.