Skip to main content

U.S. Officials Partner With CrowdStrike to Disrupt Crypto-Theft Malware



U.S. federal law enforcement says it has helped disrupt a long-running cybercrime operation tied to cryptocurrency theft, working alongside international partners and private-sector cybersecurity experts. The Justice Department announced that the Sality malware and its botnet infrastructure were targeted in an effort spanning multiple countries.



According to the U.S. Justice Department, the operation involved Bulgarian, Hungarian and Romanian authorities, as well as partners including CrowdStrike and the Shadowserver Foundation. The department said Sality was used to compromise devices and facilitate theft of digital assets, with activity traced back to 2003.



Key takeaways



  • The U.S. Justice Department said it disrupted the Sality botnet and associated malware in an international takedown effort.

  • CrowdStrike linked the scheme to clipjacking behavior that targets cryptocurrency wallet addresses copied to a clipboard.

  • U.S. officials and CrowdStrike described a peer-to-peer botnet of roughly 15,000 infected computers checking connectivity every 40 minutes.

  • CrowdStrike reported at least 12.1 million rubles (about $150,000) stolen over an eight-year period tied to “never-spent” digital assets, with a peak value around January 2025.



What the Justice Department says was targeted


In a Tuesday notice, the U.S. Justice Department stated that it had “disrupted the Sality botnet and malware” through a coordinated international operation. The department’s announcement names government agencies in Bulgaria, Hungary and Romania, while also citing private-sector support from CrowdStrike and the Shadowserver Foundation.



Officials said Sality malware was responsible for installing malicious code on compromised systems. They tied that activity to both cryptocurrency theft and broader cyberattacks. While the announcement frames the action as a disruption rather than a total elimination, the message is clear: the takedown interfered with the malware’s ability to coordinate with infected machines.



The announcement also underscores why botnets remain a key threat vector for the crypto sector. Malware operators can use compromised endpoints to manipulate users and move stolen assets, turning ordinary wallet operations—like copy-and-paste—into moments of vulnerability.



The clipjacking mechanism behind the crypto theft


CrowdStrike provided technical detail on how actors behind Sality allegedly harvested cryptocurrency payments. In a post describing the operation, the company said the criminals used EggJagger, described as a “clipjacking tool” that monitors a device’s clipboard for cryptocurrency wallet addresses.



The method is designed to be difficult for victims to notice. When a user copies a Bitcoin or Ethereum address to send funds, CrowdStrike said the malware can silently replace that address with one controlled by the attacker. In its explanation, CrowdStrike said that “funds are redirected” when the victim pastes the altered destination address into a payment.



This matters for investors and users because it highlights a persistent class of wallet-related risk: attacks do not always require users to install obviously malicious software. Instead, they can compromise normal device behavior and quietly reroute transactions.



Scale and operational details described by CrowdStrike


CrowdStrike said that in the eight years preceding the disruption, the operators behind Sality used EggJagger to steal at least 12.1 million rubles—about $150,000 in cryptocurrency—by redirecting copied wallet addresses. The company also reported that the value of the “never-spent” digital assets peaked at about $1.5 million in January 2025.



Officials and CrowdStrike described a network architecture built around peer-to-peer communication. In their account, around 15,000 infected computers formed a botnet that would check whether systems were online every 40 minutes. The operational cadence is notable: such periodic communication patterns often help attackers maintain control while keeping command-and-control traffic manageable.



As a result of the authorities’ efforts, CrowdStrike and U.S. officials said the criminals “lost the ability to communicate with infected machines.” That shift is a practical outcome of takedowns: even if some malware remains on endpoints, the attacker’s capacity to coordinate, update tactics, or manage automated theft can be severely reduced.



Why this takedown is significant for crypto security


Criminal ecosystems built around clipboard manipulation reflect a larger reality for the cryptocurrency space: user behavior and device integrity are often the weakest links. The Sality/EggJagger case demonstrates that even basic actions—copying addresses—can become an attack surface when malware is present.



For defenders, the episode reinforces the importance of hardening endpoints and monitoring for suspicious clipboard activity, not just traditional signs of malware infection. For crypto users, it strengthens the case for safer transfer practices such as verifying addresses through trusted channels and being cautious when transactions are prepared on potentially compromised systems.



From a broader market perspective, disruptions like this can reduce the flow of stolen assets—though the exact immediate impact is hard to quantify from public reporting alone. What is clear from the announcements is that law enforcement and security researchers were able to interfere with a mature cybercrime setup that had been active for years.



Looking ahead, readers should watch for two things: whether additional reporting clarifies how many victims were impacted in total, and whether security teams publish indicators or mitigation guidance connected to Sality and EggJagger techniques. As the ability to communicate with infected machines has been disrupted, the more enduring question is how quickly attackers will attempt to reconstitute similar clipboard-stealing capabilities elsewhere.



https://www.cryptobreaking.com/u-s-officials-partner-with/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=U.S.%20Officials%20Partner%20With%20CrowdStrike%20to%20Disrupt%20Crypto-Theft%20Malware%20

Comments

Popular posts from this blog

Mastercard Launches AI Agent Pay System With Ripple and Solana Help

Mastercard has launched Agent Pay for Machines, a payments system built for autonomous software agents. The service allows AI agents to send and receive payments without direct human action. It brings Ripple, Coinbase, and Solana Foundation into Mastercard’s push for automated digital commerce. Ripple Brings XRPL and RLUSD to Mastercard’s Agent Pay System Mastercard introduced Agent Pay for Machines on June 10 as a tool for machine-led payments. The system targets high-volume and low-value transactions across business and consumer use cases. It also supports automated settlement between software agents and connected machines. Ripple will support the system through the XRP Ledger and its RLUSD stablecoin. The company said that settlement will become more important as automated commerce grows. It also sees blockchain rails as useful for fast and rule-based payments. RippleX senior vice president Markus Infanger said XRPL and RLUSD support enterprise-grade agent payments. He said the tool...

Top Cryptocurrencies to Watch: BTC, ETH, BNB, XRP, Solana, Dogecoin & More

Market Analysis and Price Predictions for Key Cryptocurrencies Recent market dynamics reveal a cautious sentiment across the cryptocurrency landscape, with Bitcoin struggling to maintain levels above $90,000 and many major altcoins facing downward pressure. Indicators point toward reduced participation from both institutional and retail investors, raising concerns about a potential consolidation phase after notable gains earlier in the year. Bitcoin has fallen below $87,000, reflecting waning demand at higher price points. Institutional fund flows into BTC and ETH ETFs have turned negative, indicating a period of subdued market activity. Active addresses and Binance deposit/withdrawal activities are at annual lows, suggesting market indecision. Most leading altcoins are approaching support levels, with some poised for potential breakdowns. Tickers mentioned: Bitcoin, Ethereum, Binance Coin, XRP, Solana, Dogecoin, Cardano, Bitcoin Cash, Chainlink, Hyperliquid Sentiment: Neutral to Sli...

XRP vs. SOL: Massive Market Interest Gap Revealed by Exec

Here's the revised article with an introduction, key takeaways, and optimized for readability, SEO, and journalistic integrity while preserving the original HTML structure: --- As the crypto market continues to evolve, investor preferences remain primarily anchored around Bitcoin and Ethereum, with questions surrounding the next wave of promising digital assets. Recent insights from Coinbase Asset Management highlight the current sentiment and potential candidates vying for a top position in the rapidly expanding blockchain ecosystem. From institutional interest to network development, the race is on to identify the next asset that could join the ranks of dominant cryptocurrencies like Bitcoin and Ethereum. Investors predominantly view Bitcoin and Ethereum as the primary crypto assets for portfolio inclusion. Solana is seen as a tentative third choice, with XRP potentially vying for the next spot pending network growth. Ripple’s XRP is making strides, but market con...