US and global partners disrupt Sality malware used to steal $150,000 in crypto

US and global partners disrupt Sality malware used to steal $150,000 in crypto

US federal authorities, working with CrowdStrike and international partners, have disrupted the Sality botnet, a long-running malware operation used to steal cryptocurrency.

How the crypto theft worked

The group behind Sality used a tool called EggJagger to monitor users’ clipboards for cryptocurrency wallet addresses. When a victim copied a Bitcoin or Ethereum address to make a payment, the malware silently replaced it with an address controlled by the attackers, redirecting the funds.

Key numbers

  • About $150,000 in cryptocurrency stolen over the past eight years.
  • At its peak in January 2025, the stolen but unspent assets were worth roughly $1.5 million.
  • The botnet included about 15,000 infected computers checking in every 40 minutes.

Official action

The US Justice Department announced the takedown in coordination with Bulgarian, Hungarian, and Romanian officials, along with private-sector partners CrowdStrike and the Shadowserver Foundation. Authorities said the operation cut off the criminals’ ability to communicate with infected machines.

Sality has been active since 2003, installing malware on compromised devices to enable crypto theft and other cyberattacks.

Sources

YA
Written by

Yasir Arafat

Owner & Developer
View all posts

Yasir Arafat is a software developer and the founder of Newisty, covering web development, software, online tools and digital technology. He also oversees Newisty's publishing, technical development and editorial process.


Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!