US federal authorities say they have disrupted the Sality botnet in a cross-border operation targeting malware tied to cryptocurrency theft. The action involved law enforcement agencies in Bulgaria, Hungary and Romania, along with cybersecurity firm CrowdStrike and the nonprofit Shadowserver Foundation.
According to the US Justice Department, Sality had been used since 2003 to install malware on compromised devices, supporting both cyberattacks and the theft of digital assets. CrowdStrike said the operation cut the operators off from infected machines that had formed part of a peer-to-peer botnet.
Joint action against long-running malware
The Justice Department announced the disruption in a notice released Tuesday, describing it as an international effort between US officials, European counterparts and private-sector partners. The agencies involved included authorities in Bulgaria, Hungary and Romania, while CrowdStrike and the Shadowserver Foundation assisted on the technical side.
Officials said Sality was a long-running malware operation. In addition to broader malicious activity, US authorities linked it to cryptocurrency theft carried out through infected devices.
How the theft worked
CrowdStrike said the operators used a tool known as EggJagger over the past eight years. The company described EggJagger as a clipjacking program that watches a victim’s clipboard for cryptocurrency wallet addresses and then silently swaps them for addresses controlled by the attacker.
That means a user attempting to send funds could copy a Bitcoin or Ethereum address as usual, but the pasted destination would be changed without obvious warning. CrowdStrike said this method redirected payments to the operators’ wallets.
Amounts identified by CrowdStrike
CrowdStrike reported that the campaign stole at least 12.1 million rubles, or roughly $150,000, in cryptocurrency. The company also said the stolen digital assets were never spent.
Based on CrowdStrike’s account, the value of those holdings later rose with market prices, reaching a peak of about $1.5 million in January 2025. The article did not say whether authorities recovered those assets.
Botnet access reportedly severed
CrowdStrike said the disruption caused the people behind Sality to lose the ability to communicate with infected computers. US officials and the company said roughly 15,000 machines had been part of the peer-to-peer botnet.
According to CrowdStrike, those systems checked in every 40 minutes to confirm that they were online. By interrupting that communication, authorities aimed to break the operators’ control over the infected network.
What is confirmed next
The confirmed outcome so far is the disruption of the botnet infrastructure and the reported loss of operator access to infected machines. The Justice Department’s announcement framed the action as a coordinated law enforcement and cybersecurity effort rather than a final accounting of all harm tied to Sality.
No further enforcement steps, charges or asset seizures were detailed in the source report. For now, the key confirmed facts are the botnet takedown, the involvement of multiple national authorities and partners, and CrowdStrike’s estimate of the crypto theft connected to EggJagger.
Source: cointelegraph.com