Cointelegraph
DOGE$0.08177 0.28%
TRX$0.3247 0.51%
LINK$11.12 0.43%
ZEC$816.13 0.74%
ADA$0.1992 1.85%
XRP$1.35 0.26%
ETH$2,392.32 0.85%
BTC$77,350.69 0.25%
XMR$500.78 0.97%
BNB$687.50 1.05%
XLM$0.1747 0.35%
SOL$99.72 0.28%
HYPE$81.78 0.53%
Written by Turner Wrightstaff writerReviewed by Sam Bourgistaff writer

US officials work with CrowdStrike to fight malware behind crypto theft

Latest NewsPublishedSep 2, 2026

Federal authorities and private-sector partners were part of an operation to disrupt malware that redirected about $150,000 in crypto over the last eight years.

Federal law enforcement officials, working with cybersecurity technology company CrowdStrike, announced action against entities behind malware that enabled the theft of $150,000 in cryptocurrency.

In a Tuesday notice, the US Justice Department said it had disrupted the Sality botnet and malware in an international effort with Bulgarian, Hungarian and Romanian officials, as well as private sector partners CrowdStrike and the Shadowserver Foundation. US officials said that Sality was responsible for installing malware on compromised devices since 2003, resulting in crypto theft and cyberattacks. 

CrowdStrike reported that in the previous eight years, the entities behind Sality used EggJagger, a “clipjacking tool that monitors the clipboard for cryptocurrency wallet addresses and silently replaces them with addresses controlled by the operator,” to steal at least 12.1 million rubles, or about $150,000, in cryptocurrency. According to the company, the value of the “never-spent” digital assets peaked at about $1.5 million in January 2025.

“When a victim copies a Bitcoin or Ethereum address to make a payment, the funds are redirected,” said CrowdStrike, explaining the technique behind the theft.

According to CrowdStrike, the criminals behind Sality “lost the ability to communicate with infected machines” as a result of authorities’ efforts to disrupt the network. US officials and the company said Sality was used to steal crypto, while about 15,000 infected computers formed part of a peer-to-peer botnet that checked whether its systems were online every 40 minutes.

Related: A fake crypto job interview nearly installed malware on my computer

1 minute letter

Subscribe to daily byte-sized crypto news from Cointelegraph

Subscribe
Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.

More on the subject