US officials work with CrowdStrike to fight malware behind crypto theft

US officials work with CrowdStrike to fight malware behind crypto theft img1
Spread the love

Written by Turner Wrightstaff writerReviewed by Sam Bourgistaff writer

Written by Turner Wrightstaff writer

Reviewed by Sam Bourgistaff writer

US officials work with CrowdStrike to fight malware behind crypto theft

Latest NewsPublishedSep 2, 2026

Federal authorities and private-sector partners were part of an operation to disrupt malware that redirected about $150,000 in crypto over the last eight years.

Federal law enforcement officials, working with cybersecurity technology company CrowdStrike, revealed action against entities behind malware that enabled the theft of $150,000 in cryptocurrency.

In a Tuesday notice, the US Justice Department stated it had disrupted the Sality botnet and malware in an international effort with Bulgarian, Hungarian and Romanian officials, as well as private sector partners CrowdStrike and the Shadowserver Foundation. US officials stated that Sality was responsible for installing malware on compromised devices since 2003, resulting in crypto theft and cyberattacks. 

CrowdStrike reported that in the previous eight years, the entities behind Sality used EggJagger, a “clipjacking tool that monitors the clipboard for cryptocurrency wallet addresses and silently replaces them with addresses controlled by the operator,” to steal at least 12.1 million rubles, or about $150,000, in cryptocurrency. as reported by the company, the value of the “never-spent” digital assets peaked at about $1.5 million in January 2025.

“When a victim copies a Bitcoin or Ethereum address to make a payment, the funds are redirected,” stated CrowdStrike, explaining the technique behind the theft.

as reported by CrowdStrike, the criminals behind Sality “lost the ability to communicate with infected machines” as a result of authorities’ efforts to disrupt the network. US officials and the company stated Sality was used to steal crypto, while about 15,000 infected computers formed part of a peer-to-peer botnet that checked whether its systems were online every 40 minutes.

Related: A fake crypto job interview nearly installed malware on my computer

1 minute letter

1 minute letter

Subscribe to daily byte-sized crypto news from Cointelegraph

Subscribe

Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.

  • Crimes
  • Malware
  • United States
  • Cryptocurrencies
  • Regulation

More on the subject

New Jersey officials petition US Supreme Court over prediction markets



2 hours ago

Turner Wright

Ondo urges SEC, CFTC to bring US stock perpetuals onshore



5 hours ago

Nate Kostar

G20 members tout ‘clear pathways’ for digital asset innovation



6 hours ago

Turner Wright

New Jersey officials petition US Supreme Court over prediction markets



2 hours ago

Turner Wright

Ondo urges SEC, CFTC to bring US stock perpetuals onshore



5 hours ago

Nate Kostar

G20 members tout ‘clear pathways’ for digital asset innovation



6 hours ago

Turner Wright


💡 A Greener Way to Earn: Looking for a smarter, more sustainable way to earn and mining crypto? EcoPool Network is a cloud-based mining pool that does the heavy lifting on remote servers — so you earn rewards around the clock without worrying about overheating hardware or sky-high electricity bills. It’s lightweight, battery-friendly, and built for everyday users. Download EcoPool now and start mining & earning smarter today.

Spread the love

About the Author

Leave a Reply

Your email address will not be published. Required fields are marked *

You may also like these