Crypto news report · source clearly identified

US Authorities and CrowdStrike Disrupt Sality Botnet Behind Crypto Clipboard Hijacking

Federal law enforcement, together with cybersecurity firm CrowdStrike and international partners, dismantled the Sality botnet that used the EggJagger tool to steal roughly $150,000 in cryptocurrency over eight years.

U.S. federal officials announced the disruption of the Sality botnet, a long‑running malware network that hijacked cryptocurrency wallet addresses via a clipboard‑monitoring tool called EggJagger.

Operation Overview

The Justice Department disclosed that the takedown was carried out in coordination with cybersecurity company CrowdStrike, the Shadowserver Foundation, and law‑enforcement agencies from Bulgaria, Hungary and Romania.

How the Malware Operated

Since 2003, Sality installed malicious code on compromised devices. The EggJagger component monitored users’ clipboard activity and silently replaced copied Bitcoin or Ethereum addresses with those controlled by the attackers.

Financial Impact

  • At least 12.1 million Russian rubles (about $150,000) were diverted to the criminals.
  • The “never‑spent” stolen assets peaked at roughly $1.5 million in January 2025.

Scale of the Botnet

Approximately 15,000 infected computers formed a peer‑to‑peer network that checked in every 40 minutes. Disruption of the command infrastructure has reportedly cut off the attackers’ ability to communicate with the infected machines.

Implications

The operation highlights the role of international cooperation in combating crypto‑related malware and underscores ongoing risks associated with clipboard‑based address hijacking.

Source & attribution

News Source

Publisher
Cointelegraph
Original date
September 2, 2026, 9:27 PM
Original headline
US officials work with CrowdStrike to fight malware behind crypto theft
View original report ↗