U.S. federal law enforcement says it has helped disrupt a long-running cybercrime operation tied to cryptocurrency theft, working alongside international partners and private-sector cybersecurity experts. The Justice Department announced that the Sality malware and its botnet infrastructure were targeted in an effort spanning multiple countries.
According to the U.S. Justice Department, the operation involved Bulgarian, Hungarian and Romanian authorities, as well as partners including CrowdStrike and the Shadowserver Foundation. The department said Sality was used to compromise devices and facilitate theft of digital assets, with activity traced back to 2003.
Key takeaways
- The U.S. Justice Department said it disrupted the Sality botnet and associated malware in an international takedown effort.
- CrowdStrike linked the scheme to clipjacking behavior that targets cryptocurrency wallet addresses copied to a clipboard.
- U.S. officials and CrowdStrike described a peer-to-peer botnet of roughly 15,000 infected computers checking connectivity every 40 minutes.
- CrowdStrike reported at least 12.1 million rubles (about $150,000) stolen over an eight-year period tied to “never-spent” digital assets, with a peak value around January 2025.
What the Justice Department says was targeted
In a Tuesday notice, the U.S. Justice Department stated that it had “disrupted the Sality botnet and malware” through a coordinated international operation. The department’s announcement names government agencies in Bulgaria, Hungary and Romania, while also citing private-sector support from CrowdStrike and the Shadowserver Foundation.
Officials said Sality malware was responsible for installing malicious code on compromised systems. They tied that activity to both cryptocurrency theft and broader cyberattacks. While the announcement frames the action as a disruption rather than a total elimination, the message is clear: the takedown interfered with the malware’s ability to coordinate with infected machines.
The announcement also underscores why botnets remain a key threat vector for the crypto sector. Malware operators can use compromised endpoints to manipulate users and move stolen assets, turning ordinary wallet operations—like copy-and-paste—into moments of vulnerability.
The clipjacking mechanism behind the crypto theft
CrowdStrike provided technical detail on how actors behind Sality allegedly harvested cryptocurrency payments. In a post describing the operation, the company said the criminals used EggJagger, described as a “clipjacking tool” that monitors a device’s clipboard for cryptocurrency wallet addresses.
The method is designed to be difficult for victims to notice. When a user copies a Bitcoin or Ethereum address to send funds, CrowdStrike said the malware can silently replace that address with one controlled by the attacker. In its explanation, CrowdStrike said that “funds are redirected” when the victim pastes the altered destination address into a payment.
This matters for investors and users because it highlights a persistent class of wallet-related risk: attacks do not always require users to install obviously malicious software. Instead, they can compromise normal device behavior and quietly reroute transactions.
Scale and operational details described by CrowdStrike
CrowdStrike said that in the eight years preceding the disruption, the operators behind Sality used EggJagger to steal at least 12.1 million rubles—about $150,000 in cryptocurrency—by redirecting copied wallet addresses. The company also reported that the value of the “never-spent” digital assets peaked at about $1.5 million in January 2025.
Officials and CrowdStrike described a network architecture built around peer-to-peer communication. In their account, around 15,000 infected computers formed a botnet that would check whether systems were online every 40 minutes. The operational cadence is notable: such periodic communication patterns often help attackers maintain control while keeping command-and-control traffic manageable.
As a result of the authorities’ efforts, CrowdStrike and U.S. officials said the criminals “lost the ability to communicate with infected machines.” That shift is a practical outcome of takedowns: even if some malware remains on endpoints, the attacker’s capacity to coordinate, update tactics, or manage automated theft can be severely reduced.
Why this takedown is significant for crypto security
Criminal ecosystems built around clipboard manipulation reflect a larger reality for the cryptocurrency space: user behavior and device integrity are often the weakest links. The Sality/EggJagger case demonstrates that even basic actions—copying addresses—can become an attack surface when malware is present.
For defenders, the episode reinforces the importance of hardening endpoints and monitoring for suspicious clipboard activity, not just traditional signs of malware infection. For crypto users, it strengthens the case for safer transfer practices such as verifying addresses through trusted channels and being cautious when transactions are prepared on potentially compromised systems.
From a broader market perspective, disruptions like this can reduce the flow of stolen assets—though the exact immediate impact is hard to quantify from public reporting alone. What is clear from the announcements is that law enforcement and security researchers were able to interfere with a mature cybercrime setup that had been active for years.
Looking ahead, readers should watch for two things: whether additional reporting clarifies how many victims were impacted in total, and whether security teams publish indicators or mitigation guidance connected to Sality and EggJagger techniques. As the ability to communicate with infected machines has been disrupted, the more enduring question is how quickly attackers will attempt to reconstitute similar clipboard-stealing capabilities elsewhere.
This article was originally published as U.S. Officials Partner With CrowdStrike to Disrupt Crypto-Theft Malware on Crypto Breaking News – your trusted source for crypto news, Bitcoin news, and blockchain updates.
Disclaimer: The market is risky, and investment needs to be cautious. This article does not constitute investment advice. Users should consider whether any opinions, views, or conclusions in this article are in line with their specific circumstances. Investment based on this is at their own risk.


