US officials work with CrowdStrike to fight malware behind crypto theft

Federal authorities and private-sector partners were part of an operation to disrupt malware that redirected about $150,000 in crypto over the last eight years.

Federal law enforcement officials, working with cybersecurity technology company CrowdStrike, announced action against entities behind malware that enabled the theft of $150,000 in cryptocurrency.

In a Tuesday notice, the US Justice Department said it had disrupted the Sality botnet and malware in an international effort with Bulgarian, Hungarian and Romanian officials, as well as private sector partners CrowdStrike and the Shadowserver Foundation. US officials said that Sality was responsible for installing malware on compromised devices since 2003, resulting in crypto theft and cyberattacks. 

CrowdStrike reported that in the previous eight years, the entities behind Sality used EggJagger, a “clipjacking tool that monitors the clipboard for cryptocurrency wallet addresses and silently replaces them with addresses controlled by the operator,” to steal at least 12.1 million rubles, or about $150,000, in cryptocurrency. According to the company, the value of the “never-spent” digital assets peaked at about $1.5 million in January 2025.

Read more

Leave a Reply

Your email address will not be published. Required fields are marked *

Please enter CoinGecko Free Api Key to get this plugin works.