US federal law enforcement, in cooperation with cybersecurity company CrowdStrike and international partners, announced an operation targeting the Sality malware ecosystemโan infection chain authorities say has been used for more than two decades to steal cryptocurrency and carry out cyberattacks.
In a Tuesday announcement, the US Department of Justice (DOJ) said it disrupted the Sality botnet and related malware in an international effort involving Bulgarian, Hungarian, and Romanian officials, as well as private-sector partners CrowdStrike and the Shadowserver Foundation. The DOJ linked Sality to long-running compromise activity dating back to 2003, including the installation of malware on affected devices.
Key takeaways
- The DOJ says the Sality botnet and malware infrastructure were disrupted through a coordinated international takedown.
- CrowdStrike reports that clipboard-based โclipjackingโ was used to replace cryptocurrency addresses with attacker-controlled ones.
- According to CrowdStrike, entities behind Sality stole at least 12.1 million rubles (about $150,000) over the prior eight years.
- Authorities described a peer-to-peer botnet of roughly 15,000 infected computers that periodically checked whether targets were online.
- During the operation, Sality operators reportedly lost the ability to communicate with infected machines.
Why clipboard hijacking matters for crypto security
The most consequential detail in the reporting is how the theft worked. CrowdStrike said that in the previous eight years, the operators used EggJagger, a clipjacking tool that monitors a victimโs clipboard for cryptocurrency wallet addresses and then silently swaps them for addresses controlled by the attacker.
In practical terms, the mechanism targets a common user behavior: copying and pasting wallet addresses when sending funds. According to CrowdStrike, when a victim copies a Bitcoin or Ethereum address to complete a payment, the funds are redirected to the substituted address.
This type of attack is particularly damaging because it doesnโt require the victim to sign malicious transactions or interact with a fake website in the moment. Instead, it compromises the transaction flow at the point of address entryโmeaning users who rely on clipboard copy/paste can be tricked even if they never knowingly interact with malware prompts or phishing pages.
Scope and reported impact of the Sality operation
In its write-up on the takedown, CrowdStrike said that the clipjacking approach enabled theft of at least 12.1 million rubles, or roughly $150,000 in cryptocurrency, during the period it described. The company also emphasized that stolen assets remained โnever-spent,โ meaning the seized digital funds were not later spent or otherwise moved from the attacker-linked destinations in the observed timeframe.
It further stated that the value of these โnever-spentโ assets peaked at about $1.5 million in January 2025, giving a sense of how significant the stored proceeds could become once operational theft processes are running.
While the reported theft amount and peak valuation describe only what CrowdStrike observed in its analysis, they help clarify why disrupting the botnetโs communication channels is so important: if operators canโt reliably control or maintain infections, their ability to trigger address substitutions and collect funds diminishes.
How the botnet functionedโand what the disruption changed
US officials and CrowdStrike both described Sality as a peer-to-peer botnet. According to the company, about 15,000 infected computers were part of this network, which checked whether systems were online every 40 minutes. That periodic connectivity helped ensure the malware operators could maintain visibility into infection status and, when possible, continue malicious operations.
After the authoritiesโ efforts, CrowdStrike said the criminals โlost the ability to communicate with infected machines.โ In botnet operations, that loss is often decisive: even if infected devices remain in place temporarily, removing command-and-control communications reduces the malwareโs ability to coordinate, update, and execute its most profitable functions.
The DOJโs announcement framed the disruption as part of a broader disruption of Sality malware and the botnet infrastructure tied to it, not just a removal of individual infections. For crypto users, the key takeaway is that these campaigns can persist for long periodsโDOJ said Sality was responsible for installing malware on compromised devices since 2003โso enforcement actions and technical disruptions are critical for shrinking the attackerโs operational surface.
What investors and users should watch next
This takedown highlights how cryptocurrency theft campaigns increasingly blend malware distribution with human workflow attacks like clipboard hijacking. Users should treat clipboard-based address substitution as a real threatโespecially when sending Bitcoin or Ethereum fundsโand consider validating recipient addresses through out-of-band methods (for example, checking a pasted address against a trusted source or using verification steps in wallet software).
Looking ahead, the open question is how attackers adapt if their ability to communicate with infected machines is curtailed. Readers should watch for follow-on malware variants, new clipboard hijacking tools, or broader changes in how criminals maintain access to victim devices as the Sality infrastructure disruption ripples through criminal operations.






