US Justice Department, CrowdStrike Disrupt Sality Malware Network Used to Steal Crypto
Forecast Trend Report by Period



The US Department of Justice, working with cybersecurity company CrowdStrike, has disrupted a malware network used to steal cryptocurrency.
Cointelegraph reported on September 2 that the Justice Department had completed an international operation targeting the Sality botnet and related malware. The effort involved authorities in Bulgaria, Hungary and Romania, along with private-sector partners CrowdStrike and the Shadowserver Foundation.
CrowdStrike said the operators behind Sality used a clipjacking tool known as EggJagger to steal cryptocurrency over the past eight years. The tool works by secretly replacing a cryptocurrency wallet address copied to a victim’s clipboard with one controlled by the attackers. If a victim copies a Bitcoin or Ethereum address to make a payment, the funds are sent to a different address.
The stolen cryptocurrency was worth about 121 million rubles, or roughly $150,000. The assets had never been withdrawn and remained in the wallets. As of January 2025, their value had climbed to as much as $1.5 million.
Sality has been known since 2003 for installing malware on infected devices. About 15,000 infected computers formed a peer-to-peer botnet that checked system status every 40 minutes. The operation severed the Sality operators’ communications with infected machines, CrowdStrike said.
Suehyeon Lee
shlee@bloomingbit.ioI'm reporter Suehyeon Lee, your Web3 Moderator.