Close Menu
Crypto Breaking News
    Crypto Breaking News
    • News
      • Press Release
      • Featured
      • Events
      • Exchanges
      • Bitcoin
      • Ethereum
      • Solana
      • Ripple
      • Artificial Intelligence (AI)
      • Real World Assets (RWA)
      • Markets & Finance
      • Regulation & Policy
      • Press Releases by PR Newswire
      • News by CoinPedia
      • News by Coincu
      • News by Blockchain Wire
    • Crypto
      • Companies
      • Events
      • Partners
      • Buy Crypto
      • Timers
    • Advertise
      • Submit a Press Release
      • Logos
      • About
      • Services
    • Offers
      • Marketing Services
      • Wallets & Tools
    • Account
    • Video
    • Contact
    Submit PR
    Crypto Breaking News
    Bitcoin Crypto News Ethereum

    U.S. Officials Partner With CrowdStrike to Disrupt Crypto-Theft Malware

    34 seconds ago
    FacebookTwitterLinkedInCopy Link
    News Feed
    Google NewsRSS
    U.s. Officials Partner With Crowdstrike To Disrupt Crypto-Theft Malware
    U.s. Officials Partner With Crowdstrike To Disrupt Crypto-Theft Malware

    U.S. federal law enforcement says it has helped disrupt a long-running cybercrime operation tied to cryptocurrency theft, working alongside international partners and private-sector cybersecurity experts. The Justice Department announced that the Sality malware and its botnet infrastructure were targeted in an effort spanning multiple countries.

    According to the U.S. Justice Department, the operation involved Bulgarian, Hungarian and Romanian authorities, as well as partners including CrowdStrike and the Shadowserver Foundation. The department said Sality was used to compromise devices and facilitate theft of digital assets, with activity traced back to 2003.

    Key takeaways

    • The U.S. Justice Department said it disrupted the Sality botnet and associated malware in an international takedown effort.
    • CrowdStrike linked the scheme to clipjacking behavior that targets cryptocurrency wallet addresses copied to a clipboard.
    • U.S. officials and CrowdStrike described a peer-to-peer botnet of roughly 15,000 infected computers checking connectivity every 40 minutes.
    • CrowdStrike reported at least 12.1 million rubles (about $150,000) stolen over an eight-year period tied to โ€œnever-spentโ€ digital assets, with a peak value around January 2025.

    What the Justice Department says was targeted

    In a Tuesday notice, the U.S. Justice Department stated that it had โ€œdisrupted the Sality botnet and malwareโ€ through a coordinated international operation. The departmentโ€™s announcement names government agencies in Bulgaria, Hungary and Romania, while also citing private-sector support from CrowdStrike and the Shadowserver Foundation.

    Officials said Sality malware was responsible for installing malicious code on compromised systems. They tied that activity to both cryptocurrency theft and broader cyberattacks. While the announcement frames the action as a disruption rather than a total elimination, the message is clear: the takedown interfered with the malwareโ€™s ability to coordinate with infected machines.

    The announcement also underscores why botnets remain a key threat vector for the crypto sector. Malware operators can use compromised endpoints to manipulate users and move stolen assets, turning ordinary wallet operationsโ€”like copy-and-pasteโ€”into moments of vulnerability.

    The clipjacking mechanism behind the crypto theft

    CrowdStrike provided technical detail on how actors behind Sality allegedly harvested cryptocurrency payments. In a post describing the operation, the company said the criminals used EggJagger, described as a โ€œclipjacking toolโ€ that monitors a deviceโ€™s clipboard for cryptocurrency wallet addresses.

    The method is designed to be difficult for victims to notice. When a user copies a Bitcoin or Ethereum address to send funds, CrowdStrike said the malware can silently replace that address with one controlled by the attacker. In its explanation, CrowdStrike said that โ€œfunds are redirectedโ€ when the victim pastes the altered destination address into a payment.

    This matters for investors and users because it highlights a persistent class of wallet-related risk: attacks do not always require users to install obviously malicious software. Instead, they can compromise normal device behavior and quietly reroute transactions.

    Scale and operational details described by CrowdStrike

    CrowdStrike said that in the eight years preceding the disruption, the operators behind Sality used EggJagger to steal at least 12.1 million rublesโ€”about $150,000 in cryptocurrencyโ€”by redirecting copied wallet addresses. The company also reported that the value of the โ€œnever-spentโ€ digital assets peaked at about $1.5 million in January 2025.

    Officials and CrowdStrike described a network architecture built around peer-to-peer communication. In their account, around 15,000 infected computers formed a botnet that would check whether systems were online every 40 minutes. The operational cadence is notable: such periodic communication patterns often help attackers maintain control while keeping command-and-control traffic manageable.

    As a result of the authoritiesโ€™ efforts, CrowdStrike and U.S. officials said the criminals โ€œlost the ability to communicate with infected machines.โ€ That shift is a practical outcome of takedowns: even if some malware remains on endpoints, the attackerโ€™s capacity to coordinate, update tactics, or manage automated theft can be severely reduced.

    Why this takedown is significant for crypto security

    Criminal ecosystems built around clipboard manipulation reflect a larger reality for the cryptocurrency space: user behavior and device integrity are often the weakest links. The Sality/EggJagger case demonstrates that even basic actionsโ€”copying addressesโ€”can become an attack surface when malware is present.

    For defenders, the episode reinforces the importance of hardening endpoints and monitoring for suspicious clipboard activity, not just traditional signs of malware infection. For crypto users, it strengthens the case for safer transfer practices such as verifying addresses through trusted channels and being cautious when transactions are prepared on potentially compromised systems.

    From a broader market perspective, disruptions like this can reduce the flow of stolen assetsโ€”though the exact immediate impact is hard to quantify from public reporting alone. What is clear from the announcements is that law enforcement and security researchers were able to interfere with a mature cybercrime setup that had been active for years.

    Looking ahead, readers should watch for two things: whether additional reporting clarifies how many victims were impacted in total, and whether security teams publish indicators or mitigation guidance connected to Sality and EggJagger techniques. As the ability to communicate with infected machines has been disrupted, the more enduring question is how quickly attackers will attempt to reconstitute similar clipboard-stealing capabilities elsewhere.

    Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

    Crypto Breaking News
    • Website
    • Facebook
    • X (Twitter)
    • Pinterest
    • Instagram
    • Tumblr
    • LinkedIn

    The Crypto Breaking News editorial team curates the latest news, updates, and insights from the global cryptocurrency and blockchain industry.

    Related Posts

    Us Officials Coordinate With Crowdstrike To Counter Crypto Theft Malware

    US Officials Coordinate With CrowdStrike to Counter Crypto Theft Malware

    1 hour ago
    Coinbase Rolls Out Regulated Crypto Derivatives In Canada

    Coinbase Rolls Out Regulated Crypto Derivatives in Canada

    2 hours ago
    Wyoming Requires Chainlink Proof For State-Issued Stable Tokens

    Wyoming Requires Chainlink Proof for State-Issued Stable Tokens

    3 hours ago
    Coinbase Expands Canada Crypto Futures With Up To 10x Leverage

    Coinbase Expands Canada Crypto Futures With Up To 10x Leverage

    4 hours ago
    Sec Chair Backs Clarity Act As Senate Vote Sets Crypto Rules Test

    Sec Chair Backs Clarity Act as Senate Vote Sets Crypto Rules Test

    4 hours ago
    New Jersey Asks U.s. Supreme Court To Review Prediction Markets

    New Jersey Asks U.S. Supreme Court to Review Prediction Markets

    4 hours ago

    Search Crypto News

    Featured Crypto News

    Latest News

    • U.S. Officials Partner With CrowdStrike to Disrupt Crypto-Theft Malware
    • US Officials Coordinate With CrowdStrike to Counter Crypto Theft Malware
    • Coinbase Rolls Out Regulated Crypto Derivatives in Canada
    • Wyoming Requires Chainlink Proof for State-Issued Stable Tokens
    • Coinbase Expands Canada Crypto Futures With Up To 10x Leverage
    • Sec Chair Backs Clarity Act as Senate Vote Sets Crypto Rules Test
    • New Jersey Asks U.S. Supreme Court to Review Prediction Markets
    • Bitcoin Spot Demand Slips as Price Falters Near $77K
    • Ondo Calls on SEC and CFTC to Move US Perpetual Futures Onshore
    • Full Sail Plans Wind-Down for Sui DeFi After Switchboard Incident

    Join 20,000+ Crypto Followers

    • Facebook2.4K
    • Twitter4.5K
    • Instagram7.2K
    • LinkedIn4.3K
    • Telegram55
    • Threads1000
    Kraken Pro 300x250
    Ledger

    About Crypto Breaking News

    About Crypto Breaking News

    Crypto Breaking News is a fast-growing digital media platform focused on the latest developments in cryptocurrency, blockchain, and Web3 technologies. Our goal is to provide fast, reliable, and insightful content that helps our readers stay ahead in the ever-evolving digital asset space.

    Web3 Digital L.L.C-FZ
    License Number: 2527596
    ๐Ÿ“ž +971 50 449 2025
    โœ‰๏ธ info@cryptobreaking.com
    ๐Ÿ“Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates

    FacebookX (Twitter)InstagramPinterestYouTubeTumblrBlueskyLinkedInRedditTikTokTelegramThreadsRSS

    Links

    • Crypto News
    • Submit a Press Release
    • Advertise
    • Contact Us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • Stocks Breaking News

    advertising

    © 2026 CryptoBreaking.com | All rights reserved | Powered by Web3 Digital & Osom One

    Type above and press Enter to search. Press Esc to cancel.

    Change Location
    Find awesome listings near you!