Breaking
BRWoman is arrested for illegally working as a speech therapist in CapanemaDEAfD leads in Saxony-Anhalt ahead of state elections - Left warns of shift to the rightSEMan in his 50s taken into custody after brandishing a knife and shouting in publicCNTrump threatens to strike Iran again at any timeUKNBA fines LA Clippers $30 million for salary cap violations involving Kawhi LeonardUSDriver's License Data Breach Exposes Millions on Dark Web ID Theft ServiceCNHong Kong’s Belt and Road Office focuses on infrastructure, standards, and people-to-people linksCNChildren ask AI first when doing homework, what should parents do?KRCheongju City promotes crime prevention environmental design project in 4 regionsTRTwo suspects were identified in the investigation of the attempted UAV attack on the Ukrainian cargo plane in GermanyBRWoman is arrested for illegally working as a speech therapist in CapanemaDEAfD leads in Saxony-Anhalt ahead of state elections - Left warns of shift to the rightSEMan in his 50s taken into custody after brandishing a knife and shouting in publicCNTrump threatens to strike Iran again at any timeUKNBA fines LA Clippers $30 million for salary cap violations involving Kawhi LeonardUSDriver's License Data Breach Exposes Millions on Dark Web ID Theft ServiceCNHong Kong’s Belt and Road Office focuses on infrastructure, standards, and people-to-people linksCNChildren ask AI first when doing homework, what should parents do?KRCheongju City promotes crime prevention environmental design project in 4 regionsTRTwo suspects were identified in the investigation of the attempted UAV attack on the Ukrainian cargo plane in Germany
BackUS Justice Department and CrowdStrike disrupt Sality botnet linked to $150,000 crypto theft
US Justice Department and CrowdStrike disrupt Sality botnet linked to $150,000 crypto theft
Developing
Cointelegraph55 minutes agoTech1 min read

US Justice Department and CrowdStrike disrupt Sality botnet linked to $150,000 crypto theft

Quick Look

US Justice Department, CrowdStrike, and international partners disrupted the Sality botnet, which used malware since 2003 to steal cryptocurrency via clipboard hijacking, resulting in $150,000 in theft and 15,000 infected machines in a peer-to-peer network.

AI-generated summary

Why It Matters

The Sality botnet has been active since 2003, infecting devices and enabling cyberattacks and cryptocurrency theft through clipboard hijacking techniques.

Font size

Federal law enforcement officials, working with cybersecurity technology company CrowdStrike, announced action against entities behind malware that enabled the theft of $150,000 in cryptocurrency.

In a Tuesday notice, the US Justice Department said it had disrupted the Sality botnet and malware in an international effort with Bulgarian, Hungarian and Romanian officials, as well as private sector partners CrowdStrike and the Shadowserver Foundation. US officials said that Sality was responsible for installing malware on compromised devices since 2003, resulting in crypto theft and cyberattacks.

CrowdStrike reported that in the previous eight years, the entities behind Sality used EggJagger, a “clipjacking tool that monitors the clipboard for cryptocurrency wallet addresses and silently replaces them with addresses controlled by the operator,” to steal at least 12.1 million rubles, or about $150,000, in cryptocurrency. According to the company, the value of the “never-spent” digital assets peaked at about $1.5 million in January 2025.

“When a victim copies a Bitcoin or Ethereum address to make a payment, the funds are redirected,” said CrowdStrike, explaining the technique behind the theft.

According to CrowdStrike, the criminals behind Sality “lost the ability to communicate with infected machines” as a result of authorities’ efforts to disrupt the network. US officials and the company said Sality was used to steal crypto, while about 15,000 infected computers formed part of a peer-to-peer botnet that checked whether its systems were online every 40 minutes.

What to Watch

AI outlook — possibilities, not facts

  • Authorities may pursue further legal action against individuals behind the Sality botnet

    Possible · Within weeks

Open Questions

  • Whether any individuals behind the Sality botnet have been identified or arrested
  • The full extent of financial damage beyond the reported $150,000 in cryptocurrency
  • Whether the disrupted infrastructure can be fully dismantled or may rebound

Related Topics

This article was originally published by Cointelegraph.

Related Stories

Circle warns quantum threat to blockchain signatures is growing more efficient, cites 813-qubit record
Developing·1 hour ago

Circle warns quantum threat to blockchain signatures is growing more efficient, cites 813-qubit record

Circle issued a warning that advances in quantum circuit design are reducing the resources needed to break blockchain signatures, citing a record of 813 logical qubits for ECDSA attacks. The company emphasized that migrating USDC to post-quantum cryptography requires coordination across 37 host networks, wallets, custodians, and users, as Circle cannot unilaterally change signature rules on chains like Ethereum or Solana. While NIST has standardized quantum-resistant algorithms, Circle stressed that readiness—not a predicted Q-day—is the practical trigger for migration.

CryptoSlate
2 min read
TAC Network Halt Continues After Exploit Drains Bonded Staking Pool
Developing·4 hours ago

TAC Network Halt Continues After Exploit Drains Bonded Staking Pool

The TAC network remains halted at block 24,671,475 over 10 days after an exploit drained 2,985,651,403.40 TAC (28.6% of supply) from the bonded staking pool via a balance mismatch between EVM StateDB and Cosmos SDK ledger. The attacker sold portions on BNB Chain and TON for ~1,005,774 USDT. Recovery proposes a targeted state edit to restore delegator balances using treasury reserves, but bridging and redemption remain disabled while validators await patched binary adoption.

CryptoSlate
2 min read
More on this topicsality botnet