Crypto news report · source clearly identified

Sality Botnet Dismantled After Eight Years of Stealing Bitcoin and Ethereum

CrowdStrike and the U.S. Department of Justice isolated more than 15,000 infected machines in a coordinated takedown of the Sality botnet across four countries.

A joint operation by cybersecurity firm CrowdStrike and the U.S. Department of Justice has taken down the Sality botnet, which operated for eight years and was used to steal Bitcoin and Ethereum from compromised systems.

Scope of the takedown

The effort isolated over 15,000 infected computers spanning four countries, disrupting the botnet’s ability to continue illicit cryptocurrency theft.

Impact on stolen assets

Sality was known for targeting Bitcoin (BTC) and Ethereum (ETH) wallets, siphoning funds from victims over its operational lifespan. The takedown halts further exfiltration of these assets.

Law enforcement and industry collaboration

The operation highlights the growing cooperation between law enforcement agencies and private cybersecurity firms to combat crypto‑related malware threats.

What’s next for affected users

Owners of compromised machines are advised to run reputable anti‑malware tools, change wallet credentials, and monitor their cryptocurrency accounts for unauthorized activity.

Source & attribution

News Source

Publisher
Decrypt
Original date
September 2, 2026, 11:30 AM
Original headline
Sality Botnet Dismantled After Eight Years of Stealing Bitcoin and Ethereum
View original report ↗