US officials work with CrowdStrike to fight malware behind crypto theft

Summary

US and international law enforcement, working with CrowdStrike and the Shadowserver Foundation, disrupted the Sality botnet and malware network. The Justice Department said Sality had been installing malware on compromised devices since 2003 and was linked to cyberattacks and cryptocurrency theft. CrowdStrike said the operators used EggJagger, a clipboard-hijacking tool, to swap copied Bitcoin or Ethereum wallet addresses with attacker-controlled addresses, stealing at least 12.1 million rubles, or about $150,000, over eight years. The “never-spent” crypto tied to the theft reportedly peaked at about $1.5 million in January 2025. Authorities said the disruption cut off the criminals’ ability to communicate with infected machines. About 15,000 infected computers were part of the peer-to-peer botnet.