CrowdStrike Partners with Federal Agencies to Dismantle Cryptocurrency Theft Malware
Those operating the Sality malware network and botnet deployed a "clipjacking tool" that substituted cryptocurrency wallet addresses with addresses under their control, facilitating the theft of thousands of dollars worth of digital currency.

Federal law enforcement authorities, in collaboration with cybersecurity technology firm CrowdStrike, revealed measures taken against those responsible for malicious software that facilitated the theft of $150,000 worth of cryptocurrency.
According to a Tuesday announcement, the United States Justice Department reported successfully disrupting the Sality malware and botnet through an international collaborative effort involving authorities from Bulgaria, Hungary and Romania, alongside private sector collaborators CrowdStrike and the Shadowserver Foundation. Officials from the US stated that Sality had been responsible for deploying malware on infected systems since 2003, leading to cryptocurrency theft and various cyberattacks.
CrowdStrike's findings indicated that over the past eight years, those controlling Sality utilized EggJagger, described as a "clipjacking tool that monitors the clipboard for cryptocurrency wallet addresses and silently replaces them with addresses controlled by the operator," successfully stealing a minimum of 12.1 million rubles, equivalent to approximately $150,000, in digital currency. The cybersecurity company noted that the total value of these "never-spent" cryptocurrency assets reached a peak of roughly $1.5 million during January 2025.
When a victim copies a Bitcoin or Ethereum address to make a payment, the funds are redirected
CrowdStrike
Based on CrowdStrike's assessment, the threat actors operating Sality "lost the ability to communicate with infected machines" following law enforcement's coordinated efforts to take down the malicious network. Both US authorities and the cybersecurity firm confirmed that Sality served as a vehicle for cryptocurrency theft, with approximately 15,000 compromised computers operating as components of a peer-to-peer botnet infrastructure that verified the status of its systems every 40 minutes.