Close Menu
Crypto Breaking News
    Crypto Breaking News
    • News
      • Press Release
      • Featured
      • Events
      • Exchanges
      • Bitcoin
      • Ethereum
      • Solana
      • Ripple
      • Artificial Intelligence (AI)
      • Real World Assets (RWA)
      • Markets & Finance
      • Regulation & Policy
      • Press Releases by PR Newswire
      • News by CoinPedia
      • News by Coincu
      • News by Blockchain Wire
    • Crypto
      • Companies
      • Events
      • Partners
      • Buy Crypto
      • Timers
    • Advertise
      • Submit a Press Release
      • Logos
      • About
      • Services
    • Offers
      • Marketing Services
      • Wallets & Tools
    • Account
    • Video
    • Contact
    Submit PR
    Crypto Breaking News
    Bitcoin Crypto News Ethereum

    US Officials Coordinate With CrowdStrike to Counter Crypto Theft Malware

    1 minute ago
    FacebookTwitterLinkedInCopy Link
    News Feed
    Google NewsRSS
    Us Officials Coordinate With Crowdstrike To Counter Crypto Theft Malware
    Us Officials Coordinate With Crowdstrike To Counter Crypto Theft Malware

    US federal law enforcement, in cooperation with cybersecurity company CrowdStrike and international partners, announced an operation targeting the Sality malware ecosystemโ€”an infection chain authorities say has been used for more than two decades to steal cryptocurrency and carry out cyberattacks.

    In a Tuesday announcement, the US Department of Justice (DOJ) said it disrupted the Sality botnet and related malware in an international effort involving Bulgarian, Hungarian, and Romanian officials, as well as private-sector partners CrowdStrike and the Shadowserver Foundation. The DOJ linked Sality to long-running compromise activity dating back to 2003, including the installation of malware on affected devices.

    Key takeaways

    • The DOJ says the Sality botnet and malware infrastructure were disrupted through a coordinated international takedown.
    • CrowdStrike reports that clipboard-based โ€œclipjackingโ€ was used to replace cryptocurrency addresses with attacker-controlled ones.
    • According to CrowdStrike, entities behind Sality stole at least 12.1 million rubles (about $150,000) over the prior eight years.
    • Authorities described a peer-to-peer botnet of roughly 15,000 infected computers that periodically checked whether targets were online.
    • During the operation, Sality operators reportedly lost the ability to communicate with infected machines.

    Why clipboard hijacking matters for crypto security

    The most consequential detail in the reporting is how the theft worked. CrowdStrike said that in the previous eight years, the operators used EggJagger, a clipjacking tool that monitors a victimโ€™s clipboard for cryptocurrency wallet addresses and then silently swaps them for addresses controlled by the attacker.

    In practical terms, the mechanism targets a common user behavior: copying and pasting wallet addresses when sending funds. According to CrowdStrike, when a victim copies a Bitcoin or Ethereum address to complete a payment, the funds are redirected to the substituted address.

    This type of attack is particularly damaging because it doesnโ€™t require the victim to sign malicious transactions or interact with a fake website in the moment. Instead, it compromises the transaction flow at the point of address entryโ€”meaning users who rely on clipboard copy/paste can be tricked even if they never knowingly interact with malware prompts or phishing pages.

    Scope and reported impact of the Sality operation

    In its write-up on the takedown, CrowdStrike said that the clipjacking approach enabled theft of at least 12.1 million rubles, or roughly $150,000 in cryptocurrency, during the period it described. The company also emphasized that stolen assets remained โ€œnever-spent,โ€ meaning the seized digital funds were not later spent or otherwise moved from the attacker-linked destinations in the observed timeframe.

    It further stated that the value of these โ€œnever-spentโ€ assets peaked at about $1.5 million in January 2025, giving a sense of how significant the stored proceeds could become once operational theft processes are running.

    While the reported theft amount and peak valuation describe only what CrowdStrike observed in its analysis, they help clarify why disrupting the botnetโ€™s communication channels is so important: if operators canโ€™t reliably control or maintain infections, their ability to trigger address substitutions and collect funds diminishes.

    How the botnet functionedโ€”and what the disruption changed

    US officials and CrowdStrike both described Sality as a peer-to-peer botnet. According to the company, about 15,000 infected computers were part of this network, which checked whether systems were online every 40 minutes. That periodic connectivity helped ensure the malware operators could maintain visibility into infection status and, when possible, continue malicious operations.

    After the authoritiesโ€™ efforts, CrowdStrike said the criminals โ€œlost the ability to communicate with infected machines.โ€ In botnet operations, that loss is often decisive: even if infected devices remain in place temporarily, removing command-and-control communications reduces the malwareโ€™s ability to coordinate, update, and execute its most profitable functions.

    The DOJโ€™s announcement framed the disruption as part of a broader disruption of Sality malware and the botnet infrastructure tied to it, not just a removal of individual infections. For crypto users, the key takeaway is that these campaigns can persist for long periodsโ€”DOJ said Sality was responsible for installing malware on compromised devices since 2003โ€”so enforcement actions and technical disruptions are critical for shrinking the attackerโ€™s operational surface.

    What investors and users should watch next

    This takedown highlights how cryptocurrency theft campaigns increasingly blend malware distribution with human workflow attacks like clipboard hijacking. Users should treat clipboard-based address substitution as a real threatโ€”especially when sending Bitcoin or Ethereum fundsโ€”and consider validating recipient addresses through out-of-band methods (for example, checking a pasted address against a trusted source or using verification steps in wallet software).

    Looking ahead, the open question is how attackers adapt if their ability to communicate with infected machines is curtailed. Readers should watch for follow-on malware variants, new clipboard hijacking tools, or broader changes in how criminals maintain access to victim devices as the Sality infrastructure disruption ripples through criminal operations.

    Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

    Crypto Breaking News
    • Website
    • Facebook
    • X (Twitter)
    • Pinterest
    • Instagram
    • Tumblr
    • LinkedIn

    The Crypto Breaking News editorial team curates the latest news, updates, and insights from the global cryptocurrency and blockchain industry.

    Related Posts

    Coinbase Rolls Out Regulated Crypto Derivatives In Canada

    Coinbase Rolls Out Regulated Crypto Derivatives in Canada

    1 hour ago
    Wyoming Requires Chainlink Proof For State-Issued Stable Tokens

    Wyoming Requires Chainlink Proof for State-Issued Stable Tokens

    2 hours ago
    Coinbase Expands Canada Crypto Futures With Up To 10x Leverage

    Coinbase Expands Canada Crypto Futures With Up To 10x Leverage

    3 hours ago
    Sec Chair Backs Clarity Act As Senate Vote Sets Crypto Rules Test

    Sec Chair Backs Clarity Act as Senate Vote Sets Crypto Rules Test

    3 hours ago
    New Jersey Asks U.s. Supreme Court To Review Prediction Markets

    New Jersey Asks U.S. Supreme Court to Review Prediction Markets

    3 hours ago
    Bitcoin Spot Demand Slips As Price Falters Near $77k

    Bitcoin Spot Demand Slips as Price Falters Near $77K

    4 hours ago

    Search Crypto News

    Featured Crypto News

    Latest News

    • US Officials Coordinate With CrowdStrike to Counter Crypto Theft Malware
    • Coinbase Rolls Out Regulated Crypto Derivatives in Canada
    • Wyoming Requires Chainlink Proof for State-Issued Stable Tokens
    • Coinbase Expands Canada Crypto Futures With Up To 10x Leverage
    • Sec Chair Backs Clarity Act as Senate Vote Sets Crypto Rules Test
    • New Jersey Asks U.S. Supreme Court to Review Prediction Markets
    • Bitcoin Spot Demand Slips as Price Falters Near $77K
    • Ondo Calls on SEC and CFTC to Move US Perpetual Futures Onshore
    • Full Sail Plans Wind-Down for Sui DeFi After Switchboard Incident
    • Remixpoint Sheds Ethereum, Solana, XRP, and Dogecoin in Full Bitcoin Pivot

    Join 20,000+ Crypto Followers

    • Facebook2.4K
    • Twitter4.5K
    • Instagram7.2K
    • LinkedIn4.3K
    • Telegram55
    • Threads1000
    Tangem 300x300

    About Crypto Breaking News

    About Crypto Breaking News

    Crypto Breaking News is a fast-growing digital media platform focused on the latest developments in cryptocurrency, blockchain, and Web3 technologies. Our goal is to provide fast, reliable, and insightful content that helps our readers stay ahead in the ever-evolving digital asset space.

    Web3 Digital L.L.C-FZ
    License Number: 2527596
    ๐Ÿ“ž +971 50 449 2025
    โœ‰๏ธ info@cryptobreaking.com
    ๐Ÿ“Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates

    FacebookX (Twitter)InstagramPinterestYouTubeTumblrBlueskyLinkedInRedditTikTokTelegramThreadsRSS

    Links

    • Crypto News
    • Submit a Press Release
    • Advertise
    • Contact Us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • Stocks Breaking News

    advertising

    Bitpanda
    © 2026 CryptoBreaking.com | All rights reserved | Powered by Web3 Digital & Osom One

    Type above and press Enter to search. Press Esc to cancel.

    Change Location
    Find awesome listings near you!