US Justice Department and CrowdStrike disrupt Sality botnet linked to $150,000 crypto theft
Quick Look
US Justice Department, CrowdStrike, and international partners disrupted the Sality botnet, which used malware since 2003 to steal cryptocurrency via clipboard hijacking, resulting in $150,000 in theft and 15,000 infected machines in a peer-to-peer network.
AI-generated summary
Why It Matters
The Sality botnet has been active since 2003, infecting devices and enabling cyberattacks and cryptocurrency theft through clipboard hijacking techniques.
Federal law enforcement officials, working with cybersecurity technology company CrowdStrike, announced action against entities behind malware that enabled the theft of $150,000 in cryptocurrency.
In a Tuesday notice, the US Justice Department said it had disrupted the Sality botnet and malware in an international effort with Bulgarian, Hungarian and Romanian officials, as well as private sector partners CrowdStrike and the Shadowserver Foundation. US officials said that Sality was responsible for installing malware on compromised devices since 2003, resulting in crypto theft and cyberattacks.
CrowdStrike reported that in the previous eight years, the entities behind Sality used EggJagger, a “clipjacking tool that monitors the clipboard for cryptocurrency wallet addresses and silently replaces them with addresses controlled by the operator,” to steal at least 12.1 million rubles, or about $150,000, in cryptocurrency. According to the company, the value of the “never-spent” digital assets peaked at about $1.5 million in January 2025.
“When a victim copies a Bitcoin or Ethereum address to make a payment, the funds are redirected,” said CrowdStrike, explaining the technique behind the theft.
According to CrowdStrike, the criminals behind Sality “lost the ability to communicate with infected machines” as a result of authorities’ efforts to disrupt the network. US officials and the company said Sality was used to steal crypto, while about 15,000 infected computers formed part of a peer-to-peer botnet that checked whether its systems were online every 40 minutes.
What to Watch
AI outlook — possibilities, not facts
Authorities may pursue further legal action against individuals behind the Sality botnet
Possible · Within weeks
Open Questions
- Whether any individuals behind the Sality botnet have been identified or arrested
- The full extent of financial damage beyond the reported $150,000 in cryptocurrency
- Whether the disrupted infrastructure can be fully dismantled or may rebound







