BlogArticlesCategoriesAuthors

© 2026 VEXODA. All Rights Reserved.

PrivacyTermsFAQBlog
Vexoda Support
AI Assistant · Online

Please sign in to chat with our support team.

Sign in
US Authorities Disrupt Malware Network Responsible for Crypto Theft
Market News

US Authorities Disrupt Malware Network Responsible for Crypto Theft

Vexoda

Vexoda Newsroom

19 days ago
5 min
0 Comments

A joint operation led by US officials and cybersecurity firm CrowdStrike has disrupted the Sality botnet, a malware operation responsible for stealing approximately $150,000 in cryptocurrency over the

US federal law enforcement, in collaboration with international partners and private cybersecurity experts, has announced a significant action against the Sality botnet, a long-standing malware network responsible for various cybercrimes including cryptocurrency theft. The operation, which involved authorities from Bulgaria, Hungary, and Romania, alongside cybersecurity firm CrowdStrike and the Shadowserver Foundation, successfully disrupted the network's ability to operate. This coordinated effort aims to dismantle the infrastructure that has been used to compromise devices and facilitate illicit financial activities for nearly two decades.

The Sality botnet has been active since at least 2003, evolving over the years to include sophisticated tools for exploitation. Central to the recent disruption was the takedown of "EggJagger," a specific malware component identified by CrowdStrike. This "clipjacking" tool operated by monitoring a user's clipboard, a temporary storage area for copied information. When a user copied a cryptocurrency wallet address to initiate a transaction, EggJagger would surreptitiously replace it with an address controlled by the attackers, thereby diverting funds.

Over an eight-year period, the Sality botnet, primarily through the EggJagger malware, managed to steal approximately 12.1 million Russian rubles, which equates to roughly $150,000 USD. CrowdStrike reported that the value of these "never-spent" digital assets, held by the perpetrators, reached a peak of about $1.5 million in January of 2025, indicating a significant accumulation of stolen funds. The core functionality of EggJagger exploited the common user practice of copying and pasting wallet addresses, a critical step in most cryptocurrency transactions.

The immediate impact of this operation is that the cybercriminals behind the Sality botnet have reportedly lost their capability to communicate with and control the approximately 15,000 infected machines that comprised the peer-to-peer botnet. These compromised computers were reportedly designed to check their online status every 40 minutes, forming a resilient network. By severing this command-and-control infrastructure, law enforcement aims to prevent further exploitation and gather intelligence on the network's operators.

This incident underscores the persistent threats posed by sophisticated malware to the cryptocurrency ecosystem. The prolonged operational lifespan of the Sality botnet highlights the challenges in combating entrenched cybercriminal operations. The use of clipjacking, a relatively straightforward yet effective technique, demonstrates how attackers can exploit fundamental user behaviors within the digital space to perpetrate financial crime, even against relatively niche assets like cryptocurrency.

Moving forward, traders and cryptocurrency users should remain vigilant about digital security practices. This includes double-checking all wallet addresses before confirming transactions, employing robust antivirus software, and staying informed about emerging malware threats. The ongoing efforts by law enforcement and cybersecurity firms to combat these threats are crucial, but individual diligence remains a primary line of defense against such forms of theft and fraud in the digital asset space.


Source: Cointelegraph. Summarized and rewritten by the Vexoda Newsroom. This is market news, not financial advice.

Tags

cryptocurrency theftCryptoCybersecurityLaw EnforcementMalware