U.S. federal law enforcement agencies join forces with multinational forces to combat cryptocurrency theft malware
U.S. federal law enforcement agencies said they have joined forces with international partners and private sector cybersecurity experts to successfully disrupt a long-running cybercrime operation related to cryptocurrency theft. The U.S. Department of Justice has announced that the crackdown on Sality malware and its botnet infrastructure involves multiple countries.
According to the U.S. Department of Justice, the operation involved law enforcement agencies in Bulgaria, Hungary and Romania, as well as partners including the CrowdStrike and Shadowserver Foundation. The department said Sality was used to hack into equipment and assist in the theft of digital assets, with activities dating back to 2003.
Key Points
The U.S. Department of Justice said it has successfully disrupted the Sality botnet and related malware through an international crackdown. CrowdStrike linked the criminal activity to "clipboard hijacking" targeting cryptocurrency wallet addresses copied to the clipboard. U.S. officials and CrowdStrike described a point-to-point botnet of about 15000 infected computers that check connection status every 40 minutes. CrowdStrike reported that over eight years, the amount stolen related to digital assets that were "never spent" was at least 12.1 million rubles (approximately US$150,000), with a peak value occurring around January 2025.
Targets targeted by the U.S. Department of Justice
In a notice issued Tuesday, the U.S. Department of Justice said it had "disrupted the Sality botnet and malware" through a coordinated international operation. The department's statement mentioned government agencies in Bulgaria, Hungary and Romania, as well as private sector support from the CrowdStrike and Shadowserver foundations. Officials said Sality malware is responsible for installing malicious code on infected systems. They linked the activity to cryptocurrency theft and broader cyber attacks. Although the statement characterized the operation as a "disruption" rather than a "complete cleanup," the message was clear: the strike interfered with the malware's ability to coordinate actions with infected machines.
The statement also highlights why botnets remain a key threat carrier in the cryptocurrency space. Malware operators can use infected endpoints to manipulate users and transfer stolen assets, turning ordinary wallet operations-such as copy-and-paste-into vulnerable moments.
The clipboard hijacking mechanism behind cryptocurrency theft
CrowdStrike provided technical details on how the operators behind Sality stole cryptocurrency payments. In an article describing the operation, the company said criminals used a tool called EggJagger, which is described as a "clipboard hijacking tool" that monitors cryptocurrency wallet addresses on the device's clipboard. This method is designed to be invisible to victims. CrowdStrike said that when a user copies a Bitcoin or Ethereum address to send funds, the malware can quietly replace the address with an address controlled by an attacker. In its explanation, CrowdStrike said that when victims paste the changed target address on the payment page,"funds are transferred."
This is important for investors and users because it highlights a persistent class of wallet-related risks: Attacks do not always require users to install obviously malicious software. Instead, they can disrupt normal device behavior and quietly change trading routes.
Scale and operating details described by CrowdStrike
CrowdStrike said that in the eight years before the operation collapsed, the operators behind Sality used the wallet address copied by EggJagger through redirection to steal at least 12.1 million rubles (about $150,000) of cryptocurrency. The company also reported that the value of these "never spent" digital assets peaked at approximately $1.5 million in January 2025. Officials and CrowdStrike described a network architecture based on point-to-point communications. According to them, about 15000 infected computers form a botnet that checks every 40 minutes to see if the system is online. This operating rhythm is noteworthy: This regular pattern of communication often helps attackers maintain control while keeping command and control traffic at manageable levels. As a result of law enforcement actions, CrowdStrike and U.S. officials said criminals "lost the ability to communicate with infected machines." This shift is the real result of crackdowns: Even if some malware remains on endpoints, attackers 'ability to coordinate actions, update policies, or manage automated theft is severely compromised.
Importance of this crackdown to the security of cryptocurrencies
The criminal ecosystem built around clipboard manipulation reflects a larger reality in the cryptocurrency space: User behavior and device integrity are often the biggest weaknesses. The Sality/EggJagger case shows that when malware exists, even basic operations such as copying addresses can become an attack surface. For defenders, the incident reinforces the importance of hardening endpoints and monitoring suspicious clipboard activity, rather than just focusing on traditional signs of malware infection. For cryptocurrency users, it strengthens the case for safer transfer practices, such as verifying addresses through trusted channels and exercising caution when preparing transactions on potentially infected systems. From a broader market perspective, crackdowns like this can reduce the flow of stolen assets-although its immediate and specific impact is difficult to quantify from public reports alone. What is clear from these statements is that law enforcement agencies and security researchers can interfere with a mature cybercrime system that has been active for many years.
Looking forward, readers should pay attention to two things: whether there are more reports clarifying the total number of victims affected; and whether security teams will release indicators or mitigation guidelines related to Sality and EggJagger technologies. Because communication with infected machines has been compromised, a more persistent issue is how quickly an attacker will attempt to recreate similar clipboard theft capabilities elsewhere.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC
ETH